← Vulnerability feed

Vulnerability record · CVE-2007-0169 · published 11 January 2007

CVE-2007-0169: CA BrightStor ARCserve Backup RPC buffer overflows allow remote code execution

Broadcom · Brightstor Arcserve Backup

Multiple buffer overflows exist in CA BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and Server/Business Protection Suite r2. Crafted RPC requests to opnums 0x2F and 0x75 in the Message Engine RPC service, or opnum 0xCF in the Tape Engine service, overflow buffers and can lead to arbitrary code execution. The flaw matters because these are network-facing backup services, and successful exploitation gives an unauthenticated remote attacker code execution on the backup server.

7.5 CVSS 2.0 High EPSS 70% · top 0.6% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
34References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote code execution with public exploit references and very high EPSS, though not in KEV and the product is legacy.

What it is

Multiple buffer overflows exist in CA BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and Server/Business Protection Suite r2. Crafted RPC requests to opnums 0x2F and 0x75 in the Message Engine RPC service, or opnum 0xCF in the Tape Engine service, overflow buffers and can lead to arbitrary code execution. The flaw matters because these are network-facing backup services, and successful exploitation gives an unauthenticated remote attacker code execution on the backup server.

Impact

An attacker can execute arbitrary code with the privileges of the affected RPC service, typically SYSTEM on the backup server. That yields full control of the host and potentially access to backed-up data and the backup infrastructure.

Attack surface

Reached over the network via RPC requests to the Message Engine or Tape Engine services; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is described.

Exploitation

Not listed in CISA KEV, but EPSS is 0.70037 (99.3rd percentile) and two Zero Day Initiative references are tagged Exploit, indicating public exploit information exists.

What to do

  • Apply the vendor patch referenced in the CA support notice (supportconnectw.ca.com babimpsec-notice) or upgrade to a fixed BrightStor ARCserve/Enterprise Backup release.
  • Restrict network access to the Message Engine and Tape Engine RPC services to trusted management hosts only.
  • Block or filter RPC traffic to the affected services at the perimeter and between network segments.
  • If the product is no longer supported, retire or isolate the affected backup server and migrate to a maintained platform.

Detection

  • Monitor network traffic for RPC requests to the affected services, especially opnums 0x2F, 0x75, and 0xCF.
  • Alert on unexpected or malformed RPC payloads targeting the backup server's Message Engine and Tape Engine ports.
  • Review backup server logs and host process behavior for signs of code execution or service crashes following RPC activity.
  • Use IDS/IPS signatures for known exploit traffic against CA BrightStor ARCserve RPC services.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=467
http://osvdb.org/31327
http://secunia.com/advisories/23648 Vendor Advisory
http://securitytracker.com/id?1017506
http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp Patch
http://www.kb.cert.org/vuls/id/151032 US Government Resource
http://www.kb.cert.org/vuls/id/180336 US Government Resource
http://www.securityfocus.com/archive/1/456618/100/0/threaded
http://www.securityfocus.com/archive/1/456619/100/0/threaded
http://www.securityfocus.com/archive/1/456711
http://www.securityfocus.com/bid/22005
http://www.securityfocus.com/bid/22006
http://www.vupen.com/english/advisories/2007/0154 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-003.html Exploit
http://www.zerodayinitiative.com/advisories/ZDI-07-004.html Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/31433
https://exchange.xforce.ibmcloud.com/vulnerabilities/31443
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=467
http://osvdb.org/31327
http://secunia.com/advisories/23648 Vendor Advisory
http://securitytracker.com/id?1017506
http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp Patch
http://www.kb.cert.org/vuls/id/151032 US Government Resource
http://www.kb.cert.org/vuls/id/180336 US Government Resource
http://www.securityfocus.com/archive/1/456618/100/0/threaded
http://www.securityfocus.com/archive/1/456619/100/0/threaded
http://www.securityfocus.com/archive/1/456711
http://www.securityfocus.com/bid/22005
http://www.securityfocus.com/bid/22006
http://www.vupen.com/english/advisories/2007/0154 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-003.html Exploit
http://www.zerodayinitiative.com/advisories/ZDI-07-004.html Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/31433
https://exchange.xforce.ibmcloud.com/vulnerabilities/31443

Track CVE-2007-0169 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4397CA ARCserve Backup RPC interface directory traversal enables remote command executionThe RPC interface exposed by asdbapi.dll in CA ARCserve Backup r11.1 through r12.0 fails to validate path input, allowing a .. (dot dot) sequence in …EPSS 81%analysed10.0CVE-2008-3175Broadcom brightstor arcserve backup vulnerabilityInteger underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote a…EPSS 14%10.0CVE-2008-2241Broadcom brightstor arcserve backup path traversal vulnerabilityDirectory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data…EPSS 12%10.0CVE-2007-5325Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r1…EPSS 12%10.0CVE-2007-5326Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote…EPSS 12%10.0CVE-2007-5327Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityStack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Ente…EPSS 16%10.0CVE-2007-5328Broadcom brightstor arcserve backup permissions and access controls vulnerabilityThe Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitra…EPSS 7.0%10.0CVE-2007-5329Broadcom brightstor arcserve backup vulnerabilityUnspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2007-0169), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.