Back

CVE-2017-8895

CRITICAL

In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attacker can use this vulnerability to crash the agent or potentially take control of the agent process and then the system it is running on.

Published: May 10, 2017 Modified: Jun 17, 2026
CWE-416

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
veritas backup_exec * < 14.1.1786.1126
veritas backup_exec * < 14.2.1180.3160
veritas backup_exec * < 16.0.1142.1327

GitHub Security Advisory GHSA-65x9-x5m2-cp2g

In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 71.00%

Top 1% most likely to be exploited

Threat Score 70.5 / 100

Data Sources

NVD EPSS GitHub