CVE-2007-2864 describes a critical stack-based buffer overflow vulnerability in the Anti-Virus engine of multiple CA (formerly Computer Associates) products, affecting versions before content update 30.6. This flaw allows remote attackers to execute arbitrary code by exploiting a large, invalid value in the coffFiles field of a .CAB file. With a CVSS score of 9.3 and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, exploit code is publicly available through Metasploit, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8CPE matchmatch criteria | cpe:2.3:a:broadcom:anti-virus_for_the_enterprise:8:*:*:*:*:*:*:* | ||
9.01CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_arcserve_backup:9.01:*:*:*:*:*:*:* | ||
10.5CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_arcserve_backup:10.5:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_arcserve_backup:11:*:*:*:*:*:*:* | ||
11.1CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_arcserve_backup:11.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.