Vulnerability record · CVE-2004-1172 · published 10 January 2005
CVE-2004-1172: Veritas Backup Exec Agent Browser stack buffer overflow via long hostname
SSymantec Veritas · Backup Exec
The Agent Browser component in Veritas Backup Exec 8.x and 9.x has a stack-based buffer overflow triggered by a registration request containing an overly long hostname. Because the flaw is remotely reachable without authentication and yields full code execution, it is a serious pre-auth risk for exposed backup servers.
Description
Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, allows remote attackers to execute arbitrary code via a registration request with a long hostname.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with complete confidentiality, integrity and availability impact, plus very high EPSS, makes this critical despite the absence of KEV listing.
What it is
The Agent Browser component in Veritas Backup Exec 8.x and 9.x has a stack-based buffer overflow triggered by a registration request containing an overly long hostname. Because the flaw is remotely reachable without authentication and yields full code execution, it is a serious pre-auth risk for exposed backup servers.
Impact
A remote attacker can execute arbitrary code with the privileges of the Agent Browser service, typically SYSTEM on the backup server, giving full control of the host and its backup data.
Attack surface
Reachable over the network via a crafted registration request to the Agent Browser service; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.818, 99.6th percentile) and a public exploit reference exists, indicating meaningful real-world exploitation likelihood.
What to do
- Apply the vendor hotfixes: Backup Exec 8.60.3878 Hotfix 68 or 9.1.4691 Hotfix 40, or upgrade to a supported release.
- Restrict network access to the Agent Browser service to trusted management hosts only.
- Segment backup servers from general user and internet-facing networks.
- Retire or isolate end-of-life Backup Exec 8.x/9.x installations that cannot be patched.
Detection
- Monitor for unusually long hostname fields in Agent Browser registration traffic.
- Alert on crashes or restarts of the Backup Exec Agent Browser service.
- Watch for unexpected processes or network connections spawned by the Backup Exec service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-1172 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-1172), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.