Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mcx-q5wv-mpmg

Опубликовано: 25 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized access or lateral movement within the backup infrastructure. The issue has been resolved in versions 11.32.60, 11.34.34, and 11.36.8.

A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized access or lateral movement within the backup infrastructure. The issue has been resolved in versions 11.32.60, 11.34.34, and 11.36.8.

EPSS

Процентиль: 4%
0.0002
Низкий

8.5 High

CVSS4

Дефекты

CWE-269

Связанные уязвимости

nvd
7 месяцев назад

A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized access or lateral movement within the backup infrastructure. The issue has been resolved in versions 11.32.60, 11.34.34, and 11.36.8.

EPSS

Процентиль: 4%
0.0002
Низкий

8.5 High

CVSS4

Дефекты

CWE-269