Intrusion Prevention

CA.BrightStor.ARCserve.Backup.Tape.Engine.RPC.Code.Execution

Description

This indicates an attack attempt against a buffer-overflow vulnerability in CA BrightStor ARCserve Backup.
The vulnerability is caused by improper bounds checking in the function whose opnum is 0xBF. By sending a specially crafted RPC request to the Tape Engine service, a remote attacker could overflow a buffer and execute arbitrary code on a vulnerable system.

Affected Products

CA BrightStor ARCserve Backup r11.5
CA BrightStor ARCserve Backup r11.1
CA BrightStor ARCserve Backup for Windows r11
CA BrightStor Enterprise Backup r10.5
CA BrightStor ARCserve Backup 9.01
CA Server Protection Suite r2
CA Business Protection Suite r2
CA Business Protection Suite for Microsoft Small Business Server Standard Edition r2
CA Business Protection Suite for Microsoft Small Business Server Premium Edition r2

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

CVE References

CVE-2007-0168