Vulnerability record · CVE-2007-5003 · published 1 October 2007
CVE-2007-5003: CA BrightStor ARCserve Backup for Laptops and Desktops stack buffer overflow
Broadcom · Brightstor Arcserve Backup Laptops Desktops
Multiple stack-based buffer overflows exist in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5. A remote attacker can send an overly long username or password to the rxrLogin command in rxRPC.dll, or an overly long username to GetUserInfo, to corrupt memory. The flaw matters because it is reachable over the network without authentication and can lead to arbitrary code execution.
Description
Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrary code via a long (1) username or (2) password to the rxrLogin command in rxRPC.dll, or a long (3) username argument to the GetUserInfo function.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and complete impact, combined with a very high EPSS percentile, makes this a critical risk.
What it is
Multiple stack-based buffer overflows exist in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5. A remote attacker can send an overly long username or password to the rxrLogin command in rxRPC.dll, or an overly long username to GetUserInfo, to corrupt memory. The flaw matters because it is reachable over the network without authentication and can lead to arbitrary code execution.
Impact
An unauthenticated remote attacker can execute arbitrary code with the privileges of the affected service. Successful exploitation can fully compromise the host, affecting confidentiality, integrity, and availability.
Attack surface
The vulnerability is reached over the network through the rxRPC.dll RPC interface, specifically the rxrLogin command and GetUserInfo function. No authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
The record does not list this CVE in CISA KEV, and no ransomware group usage is documented. EPSS shows a 30-day exploitation probability of 0.67204 (99.266th percentile), indicating a high likelihood of exploitation activity, though no public exploit details are provided in the record.
What to do
- Apply the vendor patches referenced in the CA security notices and supportconnect advisories.
- Restrict network access to the rxRPC service (rxRPC.dll) to trusted hosts only.
- If the product is no longer supported, upgrade to a supported version or decommission the affected component.
- Monitor for and block malformed or oversized inputs to the rxrLogin command and GetUserInfo function at network boundaries.
- Segment hosts running BrightStor ARCserve Backup for Laptops and Desktops from untrusted networks.
Detection
- Monitor network traffic for oversized username or password fields sent to the rxrLogin command or GetUserInfo function.
- Inspect process memory or crash dumps for stack corruption in rxRPC.dll.
- Alert on unexpected process creation or code execution originating from the ARCserve service process.
- Review logs for repeated failed or malformed RPC requests to the affected service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-5003 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-5003), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.