Vulnerability record · CVE-2007-0169 · published 11 January 2007
CVE-2007-0169: CA BrightStor ARCserve Backup RPC buffer overflows allow remote code execution
Broadcom · Brightstor Arcserve Backup
Multiple buffer overflows exist in CA BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and Server/Business Protection Suite r2. Crafted RPC requests to opnums 0x2F and 0x75 in the Message Engine RPC service, or opnum 0xCF in the Tape Engine service, overflow buffers and can lead to arbitrary code execution. The flaw matters because these are network-facing backup services, and successful exploitation gives an unauthenticated remote attacker code execution on the backup server.
Description
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit references and very high EPSS, though not in KEV and the product is legacy.
What it is
Multiple buffer overflows exist in CA BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and Server/Business Protection Suite r2. Crafted RPC requests to opnums 0x2F and 0x75 in the Message Engine RPC service, or opnum 0xCF in the Tape Engine service, overflow buffers and can lead to arbitrary code execution. The flaw matters because these are network-facing backup services, and successful exploitation gives an unauthenticated remote attacker code execution on the backup server.
Impact
An attacker can execute arbitrary code with the privileges of the affected RPC service, typically SYSTEM on the backup server. That yields full control of the host and potentially access to backed-up data and the backup infrastructure.
Attack surface
Reached over the network via RPC requests to the Message Engine or Tape Engine services; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is described.
Exploitation
Not listed in CISA KEV, but EPSS is 0.70037 (99.3rd percentile) and two Zero Day Initiative references are tagged Exploit, indicating public exploit information exists.
What to do
- Apply the vendor patch referenced in the CA support notice (supportconnectw.ca.com babimpsec-notice) or upgrade to a fixed BrightStor ARCserve/Enterprise Backup release.
- Restrict network access to the Message Engine and Tape Engine RPC services to trusted management hosts only.
- Block or filter RPC traffic to the affected services at the perimeter and between network segments.
- If the product is no longer supported, retire or isolate the affected backup server and migrate to a maintained platform.
Detection
- Monitor network traffic for RPC requests to the affected services, especially opnums 0x2F, 0x75, and 0xCF.
- Alert on unexpected or malformed RPC payloads targeting the backup server's Message Engine and Tape Engine ports.
- Review backup server logs and host process behavior for signs of code execution or service crashes following RPC activity.
- Use IDS/IPS signatures for known exploit traffic against CA BrightStor ARCserve RPC services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0169 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0169), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.