CVE-2024-13976
Commvault for Windows <11.20.0-11.36.0 - Code Injection
Title source: llmDescription
A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.
Scores
EPSS
0.0002
EPSS Percentile
4.8%
Classification
CWE
CWE-427
Status
draft
Timeline
Published
Jul 25, 2025
Tracked Since
Feb 18, 2026