Record summary

CVE-2007-1785 has a selected CVSS score of 7.1; EIP currently links 1 catalogued exploit.

Description

The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBCA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Remote CodeExploitDB exploitby ShirkdogNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 14