← Vulnerability feed

Vulnerability record · CVE-2017-8895 · published 10 May 2017

CVE-2017-8895: Veritas Backup Exec agents use-after-free allows remote code execution

VVeritas · Backup Exec

Veritas Backup Exec 2014, 15 and 16 contain a use-after-free flaw in multiple agents. An unauthenticated attacker can crash the agent or potentially take control of the agent process and the host system. The flaw is remotely reachable with no privileges or user interaction, making it a serious exposure for internet- or network-exposed backup infrastructure.

9.8 CVSS 3.0 Critical EPSS 71% · top 0.6% CWE-416 · Use after free
9.8CVSS 3.0 base score, v2 10.0
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attacker can use this vulnerability to crash the agent or potentially take control of the agent process and then the system it is running on.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, a public exploit, and very high EPSS make this a top-priority patch despite no KEV listing.

What it is

Veritas Backup Exec 2014, 15 and 16 contain a use-after-free flaw in multiple agents. An unauthenticated attacker can crash the agent or potentially take control of the agent process and the host system. The flaw is remotely reachable with no privileges or user interaction, making it a serious exposure for internet- or network-exposed backup infrastructure.

Impact

An attacker can cause a denial of service by crashing the agent, or potentially execute code in the agent process and pivot to full control of the underlying system.

Attack surface

Reached over the network via the affected Backup Exec agents, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.71003, 99.372 percentile) and a public Exploit-DB entry (42282) exists, indicating mature public exploit code.

What to do

  • Apply the Veritas fix referenced in VTS17-006 (upgrade to Backup Exec 2014 build 14.1.1187.1126 or later, 15 build 14.2.1180.3160 or later, or 16 FP1 or later).
  • Restrict network access to Backup Exec agent ports to trusted management hosts only.
  • Segment backup servers and agents away from general user networks and the internet.
  • Monitor agent processes for unexpected crashes or restarts and investigate immediately.

Detection

  • Alert on Backup Exec agent process crashes or unexpected restarts in host and application logs.
  • Monitor network traffic to agent ports from unauthorized or unexpected source hosts.
  • Hunt for post-exploitation behavior on backup servers, such as new processes spawned by the agent service or unusual outbound connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-8895 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27877Veritas Backup Exec Agent improper authentication via legacy SHA schemeVeritas Backup Exec before 21.2 still supported a legacy SHA authentication scheme that should have been disabled. Because that scheme is weak, an un…KEVEPSS 65%analysed8.8CVE-2021-27878Veritas Backup Exec Agent SHA authentication bypass leading to command executionVeritas Backup Exec before 21.2 contains a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication…KEVEPSS 24%analysed8.1CVE-2021-27876Veritas Backup Exec Agent authentication bypass enabling arbitrary file accessVeritas Backup Exec before 21.2 has a flaw in the SHA authentication scheme used between client and Agent. An attacker can bypass authentication and …KEVEPSS 14%analysed8.8CVE-2020-36167Veritas backup exec unrestricted file upload vulnerabilityAn issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it …EPSS 0.46%7.8CVE-2024-33673Veritas backup exec improper access control vulnerabilityAn issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search …EPSS 0.16%7.5CVE-2005-0772Veritas backup exec null pointer dereference vulnerabilityVERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of serv…EPSS 36%7.1CVE-2024-33671Veritas backup exec vulnerabilityAn issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leverag…EPSS 0.17%7.0CVE-2026-68820Windows Ancillary Function Driver for WinSock use-after-free privilege escalationThe Windows Ancillary Function Driver for WinSock (afd.sys) contains a use-after-free (CWE-416) that lets an authorized local attacker elevate privil…KEVEPSS 0.33%analysed

Source: NIST National Vulnerability Database (record CVE-2017-8895), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.