CVE-2007-3216
CA BrightStor ARCserve Backup r11.1 - Remote Code Execution via Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 6 public exploits for CVE-2007-3216.
PoCs published by Metasploit, MC, including Metasploit module exploits/windows/brightstor/lgserver_rxsuselicenseini.
AI-analyzed exploit summary This is a Metasploit module exploiting a stack buffer overflow in CA BrightStor ARCserve Backup via a malformed RPC request to execute arbitrary code. It targets Windows 2000 SP4 and includes a payload delivery mechanism.
Description
Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 allow remote attackers to execute arbitrary code via crafted arguments to the (1) rxsAddNewUser, (2) rxsSetUserInfo, (3) rxsRenameUser, (4) rxsSetMessageLogSettings, (5) rxsExportData, (6) rxsSetServerOptions, (7) rxsRenameFile, (8) rxsACIManageSend, (9) rxsExportUser, (10) rxsImportUser, (11) rxsMoveUserData, (12) rxsUseLicenseIni, (13) rxsLicGetSiteId, (14) rxsGetLogFileNames, (15) rxsGetBackupLog, (16) rxsBackupComplete, (17) rxsSetDataProtectionSecurityData, (18) rxsSetDefaultConfigName, (19) rxsGetMessageLogSettings, (20) rxsHWDiskGetTotal, (21) rxsHWDiskGetFree, (22) rxsGetSubDirs, (23) rxsGetServerDBPathName, (24) rxsSetServerOptions, (25) rxsDeleteFile, (26) rxsACIManageSend, (27) rxcReadBackupSetList, (28) rxcWriteConfigInfo, (29) rxcSetAssetManagement, (30) rxcWriteFileListForRestore, (31) rxcReadSaveSetProfile, (32) rxcInitSaveSetProfile, (33) rxcAddSaveSetNextAppList, (34) rxcAddSaveSetNextFilesPathList, (35) rxcAddNextBackupSetIncWildCard, (36) rxcGetRevisions, (37) rxrAddMovedUser, (38) rxrSetClientVersion, or (39) rxsSetDataGrowthScheduleAndFilter commands.
Exploits (6)
This is a Metasploit module exploiting a stack buffer overflow in CA BrightStor ARCserve Backup via a malformed RPC request to execute arbitrary code. It targets Windows 2000 SP4 and includes a payload delivery mechanism.
This Metasploit module exploits a stack buffer overflow in CA BrightStor ARCserve Backup for Laptops & Desktops 11.1 by sending a crafted request to multiple RPC commands, leading to arbitrary code execution.
This Metasploit module exploits a stack buffer overflow in CA BrightStor ARCserve Backup for Laptops & Desktops 11.1 via a crafted 'rxsUseLicenseIni' request. It achieves remote code execution by overwriting the return address with a target-specific address.
This Metasploit module exploits a stack buffer overflow in CA BrightStor ARCserve Backup for Laptops & Desktops 11.1 via a crafted 'rxsUseLicenseIni' request. It achieves remote code execution by overwriting the return address and executing payload shellcode.
This Metasploit module exploits a stack buffer overflow in CA BrightStor ARCserve Backup for Laptops & Desktops 11.1 by sending a crafted request to multiple RPC commands, leading to arbitrary code execution. The exploit uses SEH overwrites and a payload to achieve remote code execution.
This Metasploit module exploits a stack buffer overflow in CA BrightStor ARCserve Backup for Laptops & Desktops 11.1 via a crafted rxsSetDataGrowthScheduleAndFilter request. It sends a maliciously long payload to trigger arbitrary code execution on Windows 2000 SP4.