Exploit code released for vulnerability in CA software

By

Hackers have released exploit code for a vulnerability in CA storage software, the US Computer Emergency Response Team (US-Cert) has warned.

Exploit code released for vulnerability in CA software
The flaw affects CA’s BrightStor ARCserve Backup application and is caused by an unspecified error in the way that the “mediasvr.exe” process handles remote procedure call (RPC) requests, according to the advisory on the US-Cert website.

An attacker could exploit the vulnerability in order to gain control of the computer, the posting said. They could remotely execute code and if the exploit fails launch a denial of service attack, researchers claim.

The team advised organisations that employ the software to restrict user access to RPC until a patch is issued.
Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Palo Alto Networks in talks to buy CyberArk

Palo Alto Networks in talks to buy CyberArk

Gov to encourage vuln research, puts insurers and NFPs on notice

Gov to encourage vuln research, puts insurers and NFPs on notice

"Scattered Spider" evolves with new ransomware and social engineering tactics

"Scattered Spider" evolves with new ransomware and social engineering tactics

Allianz Life says majority of US customers' data stolen in hack

Allianz Life says majority of US customers' data stolen in hack

Log In

  |  Forgot your password?