CVE-2007-0169
BrightStor ARCserve Backup < 11.5 - Remote Code Execution via Crafted RPC Requests
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-0169.
PoCs published by Metasploit, MC, aushack, including Metasploit module exploits/windows/brightstor/message_engine.
AI-analyzed exploit summary This is a Metasploit module exploiting a buffer overflow in CA BrightStor ARCserve Backup via a crafted DCERPC request to execute arbitrary code. It targets versions 11.1 to 11.5 SP2 by overflowing a buffer with a payload and return address.
Description
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.
Exploits (2)
This is a Metasploit module exploiting a buffer overflow in CA BrightStor ARCserve Backup via a crafted DCERPC request to execute arbitrary code. It targets versions 11.1 to 11.5 SP2 by overflowing a buffer with a payload and return address.
This Metasploit module exploits a buffer overflow in CA BrightStor ARCserve Backup via a crafted DCERPC request to execute arbitrary code. It targets versions 11.1 to 11.5 SP2 by overflowing a buffer with a payload and return address.