Vulnerability record · CVE-2005-1272 · published 5 August 2005
CVE-2005-1272: BrightStor ARCserve Backup Agent for SQL Server stack buffer overflow
Broadcom · Brightstor Enterprise Backup
The Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 contains a stack-based buffer overflow reachable by sending a long string to port 6070 or 6050. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the backup server.
Description
Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely exploitable without authentication, has public exploit references, and carries a very high EPSS score, though it affects an old, likely retired product.
What it is
The Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 contains a stack-based buffer overflow reachable by sending a long string to port 6070 or 6050. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the backup server.
Impact
Successful exploitation allows remote code execution with the privileges of the vulnerable backup agent service, giving an attacker control of the host. Because the service runs on a backup server, compromise can also expose backed-up data and connected systems.
Attack surface
The flaw is reached over the network via TCP ports 6070 or 6050; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is described in the record.
Exploitation
CISA KEV does not list this CVE, but EPSS is high (0.66121, 99.24th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply the vendor patch referenced in the CA and CERT/CC advisories as soon as possible.
- If patching is not immediately possible, block or restrict access to TCP ports 6070 and 6050 to trusted hosts only.
- Isolate backup agent hosts on a management network separate from general user and internet-facing networks.
- Retire or upgrade end-of-life BrightStor ARCserve Backup Agent for SQL Server 11.0, which no longer receives vendor support.
- Monitor vendor advisories for any updated guidance affecting the affected agent.
Detection
- Monitor network traffic to TCP ports 6070 and 6050 for unusually long or malformed strings targeting the backup agent.
- Alert on unexpected process creation or crashes of the BrightStor ARCserve backup agent service on SQL Server hosts.
- Review host logs for service restarts or abnormal termination of the backup agent following inbound connections on those ports.
- Use IDS/IPS signatures for stack buffer overflow attempts against ARCserve backup agent services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.idefense.com/application/poi/display?id=287&type=vulnerabilities&flashstatus=true | |
| http://www.kb.cert.org/vuls/id/279774 | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/14453 | ExploitPatch |
| http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33239 | Patch |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/21656 | |
| http://www.idefense.com/application/poi/display?id=287&type=vulnerabilities&flashstatus=true | |
| http://www.kb.cert.org/vuls/id/279774 | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/14453 | ExploitPatch |
| http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33239 | Patch |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/21656 |
Track CVE-2005-1272 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-1272), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.