← Vulnerability feed

Vulnerability record · CVE-2007-5003 · published 1 October 2007

CVE-2007-5003: CA BrightStor ARCserve Backup for Laptops and Desktops stack buffer overflow

Broadcom · Brightstor Arcserve Backup Laptops Desktops

Multiple stack-based buffer overflows exist in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5. A remote attacker can send an overly long username or password to the rxrLogin command in rxRPC.dll, or an overly long username to GetUserInfo, to corrupt memory. The flaw matters because it is reachable over the network without authentication and can lead to arbitrary code execution.

10.0 CVSS 2.0 High EPSS 67% · top 0.7% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrary code via a long (1) username or (2) password to the rxrLogin command in rxRPC.dll, or a long (3) username argument to the GetUserInfo function.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and complete impact, combined with a very high EPSS percentile, makes this a critical risk.

What it is

Multiple stack-based buffer overflows exist in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5. A remote attacker can send an overly long username or password to the rxrLogin command in rxRPC.dll, or an overly long username to GetUserInfo, to corrupt memory. The flaw matters because it is reachable over the network without authentication and can lead to arbitrary code execution.

Impact

An unauthenticated remote attacker can execute arbitrary code with the privileges of the affected service. Successful exploitation can fully compromise the host, affecting confidentiality, integrity, and availability.

Attack surface

The vulnerability is reached over the network through the rxRPC.dll RPC interface, specifically the rxrLogin command and GetUserInfo function. No authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.

Exploitation

The record does not list this CVE in CISA KEV, and no ransomware group usage is documented. EPSS shows a 30-day exploitation probability of 0.67204 (99.266th percentile), indicating a high likelihood of exploitation activity, though no public exploit details are provided in the record.

What to do

  • Apply the vendor patches referenced in the CA security notices and supportconnect advisories.
  • Restrict network access to the rxRPC service (rxRPC.dll) to trusted hosts only.
  • If the product is no longer supported, upgrade to a supported version or decommission the affected component.
  • Monitor for and block malformed or oversized inputs to the rxrLogin command and GetUserInfo function at network boundaries.
  • Segment hosts running BrightStor ARCserve Backup for Laptops and Desktops from untrusted networks.

Detection

  • Monitor network traffic for oversized username or password fields sent to the rxrLogin command or GetUserInfo function.
  • Inspect process memory or crash dumps for stack corruption in rxRPC.dll.
  • Alert on unexpected process creation or code execution originating from the ARCserve service process.
  • Review logs for repeated failed or malformed RPC requests to the affected service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-5003 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0042Broadcom anti-spyware vulnerabilityMultiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterpr…EPSS 4.3%10.0CVE-2008-3175Broadcom brightstor arcserve backup vulnerabilityInteger underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote a…EPSS 14%10.0CVE-2008-1329Broadcom desktop management suite vulnerabilityUnspecified vulnerability in the NetBackup service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allow…EPSS 5.9%10.0CVE-2007-5005Broadcom brightstor arcserve backup laptops desktops path traversal vulnerabilityDirectory traversal vulnerability in rxRPC.dll in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 al…EPSS 5.2%10.0CVE-2007-5006Broadcom brightstor arcserve backup laptops desktops improper authentication vulnerabilityMultiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer…EPSS 21%10.0CVE-2007-3216CA BrightStor ARCserve LGServer buffer overflows allow remote code executionThe LGServer component of CA BrightStor ARCserve Backup for Laptops and Desktops r11.1 contains multiple buffer overflows reachable through crafted a…EPSS 59%analysed10.0CVE-2007-0449CA BrightStor ARCserve LGSERVER.EXE remote buffer overflowLGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops (and related CA products) contains multiple buffer overflows reachable via cra…EPSS 79%analysed10.0CVE-2006-5171Broadcom brightstor arcserve backup vulnerabilityStack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2007-5003), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.