Vulnerability record · CVE-2017-8895 · published 10 May 2017
CVE-2017-8895: Veritas Backup Exec agents use-after-free allows remote code execution
VVeritas · Backup Exec
Veritas Backup Exec 2014, 15 and 16 contain a use-after-free flaw in multiple agents. An unauthenticated attacker can crash the agent or potentially take control of the agent process and the host system. The flaw is remotely reachable with no privileges or user interaction, making it a serious exposure for internet- or network-exposed backup infrastructure.
Description
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attacker can use this vulnerability to crash the agent or potentially take control of the agent process and then the system it is running on.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, a public exploit, and very high EPSS make this a top-priority patch despite no KEV listing.
What it is
Veritas Backup Exec 2014, 15 and 16 contain a use-after-free flaw in multiple agents. An unauthenticated attacker can crash the agent or potentially take control of the agent process and the host system. The flaw is remotely reachable with no privileges or user interaction, making it a serious exposure for internet- or network-exposed backup infrastructure.
Impact
An attacker can cause a denial of service by crashing the agent, or potentially execute code in the agent process and pivot to full control of the underlying system.
Attack surface
Reached over the network via the affected Backup Exec agents, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.71003, 99.372 percentile) and a public Exploit-DB entry (42282) exists, indicating mature public exploit code.
What to do
- Apply the Veritas fix referenced in VTS17-006 (upgrade to Backup Exec 2014 build 14.1.1187.1126 or later, 15 build 14.2.1180.3160 or later, or 16 FP1 or later).
- Restrict network access to Backup Exec agent ports to trusted management hosts only.
- Segment backup servers and agents away from general user networks and the internet.
- Monitor agent processes for unexpected crashes or restarts and investigate immediately.
Detection
- Alert on Backup Exec agent process crashes or unexpected restarts in host and application logs.
- Monitor network traffic to agent ports from unauthorized or unexpected source hosts.
- Hunt for post-exploitation behavior on backup servers, such as new processes spawned by the agent service or unusual outbound connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/98386 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038561 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/42282/ | Third Party AdvisoryVDB Entry |
| https://www.veritas.com/content/support/en_US/security/VTS17-006.html#Issue1 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/98386 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038561 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/42282/ | Third Party AdvisoryVDB Entry |
| https://www.veritas.com/content/support/en_US/security/VTS17-006.html#Issue1 | PatchVendor Advisory |
Track CVE-2017-8895 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8895), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.