Vulnerability record · CVE-2007-2139 · published 25 April 2007
CVE-2007-2139: CA BrightStor ARCserve Media Server SUN RPC stack buffer overflow
Broadcom · Brightstor Arcserve Backup
The SUN RPC service in CA BrightStor ARCserve Media Server contains multiple stack-based buffer overflows triggered by malformed RPC strings. The flaw affects BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, and is distinct from CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785. Because the service is network-reachable and requires no credentials, it is a serious pre-authentication remote code execution risk for exposed backup infrastructure.
Description
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityPre-authentication remote code execution with CVSS 10.0 and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing is recorded.
What it is
The SUN RPC service in CA BrightStor ARCserve Media Server contains multiple stack-based buffer overflows triggered by malformed RPC strings. The flaw affects BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, and is distinct from CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785. Because the service is network-reachable and requires no credentials, it is a serious pre-authentication remote code execution risk for exposed backup infrastructure.
Impact
A remote attacker can execute arbitrary code with the privileges of the RPC service, typically SYSTEM on Windows hosts. That yields full control of the backup media server and a foothold into the backup environment.
Attack surface
Reached over the network through the SUN RPC service on the media server; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host that can reach the RPC port can attempt the malformed string.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is 0.77996 (99.55th percentile), indicating high predicted exploitation activity. A patch reference is present, and the Zero Day Initiative advisory suggests coordinated disclosure rather than confirmed in-the-wild use.
What to do
- Apply the vendor patch referenced in the CA support notice and SecurityFocus BID 23635 as the first action.
- Restrict network access to the SUN RPC service on media servers using host firewalls or segmentation; do not expose it to untrusted networks.
- Upgrade or retire end-of-life BrightStor ARCserve versions (9.01 through 11.5 SP2) that no longer receive vendor support.
- Run the media server service with least privilege where the platform allows, rather than SYSTEM.
- Monitor vendor advisories for follow-up fixes, since this CVE is one of several related RPC overflow issues.
Detection
- Monitor RPC traffic to the media server for malformed or oversized string parameters that deviate from normal client behavior.
- Alert on unexpected process creation or child processes spawned by the ARCserve media server service.
- Review media server logs and host telemetry for crashes or restarts of the SUN RPC service, which can indicate failed exploit attempts.
- Baseline which hosts legitimately connect to the RPC port and alert on new or unusual source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2139 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-2139), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.