← All CVEs

CVE-2007-1785

high · 7.1

The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.

7.1
CVSS
15.4%
EPSS (exploit prob.)
97th
EPSS percentile
2007-03-31
Published

AV:N/AC:H/Au:S/C:C/I:C/A:C

Affected products

VendorProductAffected versions
broadcombrightstor_arcserve_backup9.01
broadcombrightstor_arcserve_backup11.1
broadcombrightstor_arcserve_backup11.5
broadcombrightstor_arcserve_backup11.5
broadcombrightstor_arcserve_backup11.5
cabrightstor_arcserve_backup11

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-1785