2 results (0.007 seconds)

CVSS: 9.3EPSS: 0%CPEs: 2EXPL: 0

An issue was discovered in Veritas System Recovery before 21.2. On start-up, it loads the OpenSSL library from \usr\local\ssl. This library attempts to load the from \usr\local\ssl\openssl.cnf configuration file, which does not exist. By default, on Windows systems, users can create directories under C:\. A low privileged user can create a C:\usr\local\ssl\openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. • https://www.veritas.com/content/support/en_US/security/VTS20-017 •

CVSS: 9.3EPSS: 0%CPEs: 1EXPL: 0

In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker has write access to the directory from which the product is executed. En Veritas System Recovery en versiones anteriores a 16 SP1, existe una vulnerabilidad de secuestro de DLL en el instalador de revisión si un atacante tiene acceso de escritura al directorio desde el que se ejecuta el producto. • http://www.securityfocus.com/bid/97483 https://www.veritas.com/content/support/en_US/security/VTS17-001.html#Issue1 •