← Vulnerability feed

Vulnerability record · CVE-2007-0449 · published 23 January 2007

CVE-2007-0449: CA BrightStor ARCserve LGSERVER.EXE remote buffer overflow

Broadcom · Brightstor Arcserve Backup Laptops Desktops

LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops (and related CA products) contains multiple buffer overflows reachable via crafted packets to TCP ports 1900 and 2200. Successful exploitation allows remote code execution on the affected host. The flaw affects r11.0 through r11.1 SP1 and several companion products.

10.0 CVSS 2.0 High EPSS 79% · top 0.4% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port (1) 1900 or (2) 2200.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0 with network reachability, no authentication, and complete impact, combined with very high EPSS, makes this a critical risk despite no KEV listing.

What it is

LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops (and related CA products) contains multiple buffer overflows reachable via crafted packets to TCP ports 1900 and 2200. Successful exploitation allows remote code execution on the affected host. The flaw affects r11.0 through r11.1 SP1 and several companion products.

Impact

A remote, unauthenticated attacker can execute arbitrary code with the privileges of the LGSERVER.EXE service, potentially leading to full system compromise. No user interaction is required.

Attack surface

Reachable over the network via TCP ports 1900 and 2200; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is needed. No user interaction is described.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.79365, 99.58th percentile), suggesting elevated likelihood of exploitation activity. References include patch and vendor advisory tags, indicating fixes are available.

What to do

  • Apply the vendor patches referenced in the CA support notice and Secunia advisory.
  • Restrict network access to TCP ports 1900 and 2200 to trusted hosts only.
  • If the product is no longer supported, isolate or decommission affected systems.
  • Monitor for anomalous traffic to ports 1900/2200 and unexpected process behavior from LGSERVER.EXE.

Detection

  • Monitor network traffic for crafted packets targeting TCP ports 1900 and 2200.
  • Watch for crashes or restarts of LGSERVER.EXE that may indicate exploitation attempts.
  • Review host logs for unexpected child processes spawned by LGSERVER.EXE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/23897 PatchVendor Advisory
http://securitytracker.com/id?1017548
http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp Patch
http://www.kb.cert.org/vuls/id/357308 US Government Resource
http://www.kb.cert.org/vuls/id/611276 US Government Resource
http://www.osvdb.org/31593
http://www.securityfocus.com/archive/1/457945/30/8460/threaded
http://www.securityfocus.com/archive/1/458644/100/0/threaded
http://www.securityfocus.com/archive/1/458648/100/0/threaded
http://www.securityfocus.com/bid/22199
http://www.securityfocus.com/bid/22340
http://www.securityfocus.com/bid/22342
http://www.vupen.com/english/advisories/2007/0314 Vendor Advisory
http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696
http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993
https://exchange.xforce.ibmcloud.com/vulnerabilities/31704
http://secunia.com/advisories/23897 PatchVendor Advisory
http://securitytracker.com/id?1017548
http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp Patch
http://www.kb.cert.org/vuls/id/357308 US Government Resource
http://www.kb.cert.org/vuls/id/611276 US Government Resource
http://www.osvdb.org/31593
http://www.securityfocus.com/archive/1/457945/30/8460/threaded
http://www.securityfocus.com/archive/1/458644/100/0/threaded
http://www.securityfocus.com/archive/1/458648/100/0/threaded
http://www.securityfocus.com/bid/22199
http://www.securityfocus.com/bid/22340
http://www.securityfocus.com/bid/22342
http://www.vupen.com/english/advisories/2007/0314 Vendor Advisory
http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696
http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993
https://exchange.xforce.ibmcloud.com/vulnerabilities/31704

Track CVE-2007-0449 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4397CA ARCserve Backup RPC interface directory traversal enables remote command executionThe RPC interface exposed by asdbapi.dll in CA ARCserve Backup r11.1 through r12.0 fails to validate path input, allowing a .. (dot dot) sequence in …EPSS 81%analysed10.0CVE-2008-3175Broadcom brightstor arcserve backup vulnerabilityInteger underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote a…EPSS 14%10.0CVE-2008-1329Broadcom desktop management suite vulnerabilityUnspecified vulnerability in the NetBackup service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allow…EPSS 5.9%10.0CVE-2007-5326Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote…EPSS 12%10.0CVE-2007-5329Broadcom brightstor arcserve backup vulnerabilityUnspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack …EPSS 2.2%10.0CVE-2007-5331Broadcom brightstor arcserve backup code injection vulnerabilityQueue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows re…EPSS 9.9%10.0CVE-2007-5003CA BrightStor ARCserve Backup for Laptops and Desktops stack buffer overflowMultiple stack-based buffer overflows exist in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5. A remote attacker can send…EPSS 67%analysed10.0CVE-2007-5005Broadcom brightstor arcserve backup laptops desktops path traversal vulnerabilityDirectory traversal vulnerability in rxRPC.dll in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 al…EPSS 5.2%

Source: NIST National Vulnerability Database (record CVE-2007-0449), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.