Vulnerable Systems:
* Computer Associates ARCserve Backup for Windows r12.5
* Computer Associates ARCserve Backup for Windows r15
* Computer Associates ARCserve Backup for Windows r16
Successfully exploiting these issues allows remote attackers to execute arbitrary code or cause denial-of-service conditions; other attacks are also possible.
A remote user can send specially crafted RPC requests to execute arbitrary code on the target system [CVE-2012-2971]. The code will run with the privileges of the target service. Server installations are affected. A remote user can send specially crafted RPC requests to cause the target service to crash [CVE-2012-2972]. Server and agent installations are affected