CVE-2017-8895 is a critical use-after-free vulnerability affecting Veritas Backup Exec versions 2014, 15, and 16. An unauthenticated attacker can exploit this flaw in multiple agents, leading to a denial of service or remote code execution. With a CVSS score of 9.8, it presents a severe risk, allowing an attacker to crash the agent or potentially gain full control over the system. Exploit code, including a Metasploit module, is publicly available, though there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.1.1786.1126CPE matchmatch criteria | cpe:2.3:a:veritas:backup_exec:*:*:*:*:*:*:*:* | ||
< 14.2.1180.3160CPE matchmatch criteria | cpe:2.3:a:veritas:backup_exec:*:*:*:*:*:*:*:* | ||
< 16.0.1142.1327CPE matchmatch criteria | cpe:2.3:a:veritas:backup_exec:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.