← Vulnerability feed

Vulnerability record · CVE-2007-2139 · published 25 April 2007

CVE-2007-2139: CA BrightStor ARCserve Media Server SUN RPC stack buffer overflow

Broadcom · Brightstor Arcserve Backup

The SUN RPC service in CA BrightStor ARCserve Media Server contains multiple stack-based buffer overflows triggered by malformed RPC strings. The flaw affects BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, and is distinct from CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785. Because the service is network-reachable and requires no credentials, it is a serious pre-authentication remote code execution risk for exposed backup infrastructure.

10.0 CVSS 2.0 High EPSS 78% · top 0.4%
10.0CVSS 2.0 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityPre-authentication remote code execution with CVSS 10.0 and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing is recorded.

What it is

The SUN RPC service in CA BrightStor ARCserve Media Server contains multiple stack-based buffer overflows triggered by malformed RPC strings. The flaw affects BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, and is distinct from CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785. Because the service is network-reachable and requires no credentials, it is a serious pre-authentication remote code execution risk for exposed backup infrastructure.

Impact

A remote attacker can execute arbitrary code with the privileges of the RPC service, typically SYSTEM on Windows hosts. That yields full control of the backup media server and a foothold into the backup environment.

Attack surface

Reached over the network through the SUN RPC service on the media server; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host that can reach the RPC port can attempt the malformed string.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is 0.77996 (99.55th percentile), indicating high predicted exploitation activity. A patch reference is present, and the Zero Day Initiative advisory suggests coordinated disclosure rather than confirmed in-the-wild use.

What to do

  • Apply the vendor patch referenced in the CA support notice and SecurityFocus BID 23635 as the first action.
  • Restrict network access to the SUN RPC service on media servers using host firewalls or segmentation; do not expose it to untrusted networks.
  • Upgrade or retire end-of-life BrightStor ARCserve versions (9.01 through 11.5 SP2) that no longer receive vendor support.
  • Run the media server service with least privilege where the platform allows, rather than SYSTEM.
  • Monitor vendor advisories for follow-up fixes, since this CVE is one of several related RPC overflow issues.

Detection

  • Monitor RPC traffic to the media server for malformed or oversized string parameters that deviate from normal client behavior.
  • Alert on unexpected process creation or child processes spawned by the ARCserve media server service.
  • Review media server logs and host telemetry for crashes or restarts of the SUN RPC service, which can indicate failed exploit attempts.
  • Baseline which hosts legitimately connect to the RPC port and alert on new or unusual source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2139 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4397CA ARCserve Backup RPC interface directory traversal enables remote command executionThe RPC interface exposed by asdbapi.dll in CA ARCserve Backup r11.1 through r12.0 fails to validate path input, allowing a .. (dot dot) sequence in …EPSS 81%analysed10.0CVE-2008-3175Broadcom brightstor arcserve backup vulnerabilityInteger underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote a…EPSS 14%10.0CVE-2008-2241Broadcom brightstor arcserve backup path traversal vulnerabilityDirectory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data…EPSS 12%10.0CVE-2007-5325Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r1…EPSS 12%10.0CVE-2007-5326Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote…EPSS 12%10.0CVE-2007-5327Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityStack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Ente…EPSS 16%10.0CVE-2007-5328Broadcom brightstor arcserve backup permissions and access controls vulnerabilityThe Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitra…EPSS 7.0%10.0CVE-2007-5329Broadcom brightstor arcserve backup vulnerabilityUnspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2007-2139), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.