Vulnerability record · CVE-2007-0449 · published 23 January 2007
CVE-2007-0449: CA BrightStor ARCserve LGSERVER.EXE remote buffer overflow
Broadcom · Brightstor Arcserve Backup Laptops Desktops
LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops (and related CA products) contains multiple buffer overflows reachable via crafted packets to TCP ports 1900 and 2200. Successful exploitation allows remote code execution on the affected host. The flaw affects r11.0 through r11.1 SP1 and several companion products.
Description
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port (1) 1900 or (2) 2200.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0 with network reachability, no authentication, and complete impact, combined with very high EPSS, makes this a critical risk despite no KEV listing.
What it is
LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops (and related CA products) contains multiple buffer overflows reachable via crafted packets to TCP ports 1900 and 2200. Successful exploitation allows remote code execution on the affected host. The flaw affects r11.0 through r11.1 SP1 and several companion products.
Impact
A remote, unauthenticated attacker can execute arbitrary code with the privileges of the LGSERVER.EXE service, potentially leading to full system compromise. No user interaction is required.
Attack surface
Reachable over the network via TCP ports 1900 and 2200; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is needed. No user interaction is described.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.79365, 99.58th percentile), suggesting elevated likelihood of exploitation activity. References include patch and vendor advisory tags, indicating fixes are available.
What to do
- Apply the vendor patches referenced in the CA support notice and Secunia advisory.
- Restrict network access to TCP ports 1900 and 2200 to trusted hosts only.
- If the product is no longer supported, isolate or decommission affected systems.
- Monitor for anomalous traffic to ports 1900/2200 and unexpected process behavior from LGSERVER.EXE.
Detection
- Monitor network traffic for crafted packets targeting TCP ports 1900 and 2200.
- Watch for crashes or restarts of LGSERVER.EXE that may indicate exploitation attempts.
- Review host logs for unexpected child processes spawned by LGSERVER.EXE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0449 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0449), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.