CA Multiple Product Discovery Service Buffer Overflow
8 Oct. 2006
Summary
LSsec has discovered a vulnerability in Computer Associates BrightStor ARCserve Backup, which could be exploited by an anonymous attacker in order to execute arbitrary code with SYSTEM privileges on an affected system. The flaw specifically exists within the Message Engine (msgeng.exe) due to incorrect handling of RPC requests on TCP port 6503. The interface is identified by dc246bf0-7a7a-11ce-9f88-00805fe43838. Opnum 43 specifies the vulnerable operation within this interface.
Vulnerable Systems:
* BrightStor ARCserve Backup version R11.5 Client
* BrightStor ARCserve Backup version R11.5 Server
* BrightStor Enterprise Backup version 10.5
* BrightStor ARCserve Backup version 9.01
* CA Server Protection Suite r2
* CA Business Protection Suite r2