CVE-2024-0799

Vulnerability updated 6 months ago (2024-11-29T14:33:53.929Z)
Download STIX
Preview STIX
CVE-2024-0799 is a critical security vulnerability identified in the software design and implementation of Arcserve's Unified Data Protection (UDP) solution, a widely used enterprise backup and disaster recovery system. This flaw could potentially allow an attacker to upload malicious files to the underlying Windows system. The vulnerability was one among three discovered vulnerabilities (CVE-2024-0799, CVE-2024-0800, CVE-2024-0801), all of which posed serious threats to the integrity and security of data managed by the UDP solution. Arcserve promptly addressed these security vulnerabilities, with fixes being applied particularly for CVE-2024-0799 and CVE-2024-0800, as reported on March 14, 2024. These patches prevent the chaining of these vulnerabilities to compromise the system. By doing so, they have mitigated the risk of unauthorized file uploads that could jeopardize the security of the Windows system running the UDP solution. Despite the prompt response from Arcserve, the publication of Proof of Concept (PoC) for these vulnerabilities (CVE-2024-0799, CVE-2024-0800) has raised concerns. The dissemination of this information might equip potential attackers with knowledge on exploiting these vulnerabilities. Therefore, it is of utmost importance for all users of Arcserve UDP solution to apply the provided patches immediately to ensure their systems are secure against these vulnerabilities.
Description last updated: 2024-05-05T01:07:59.194Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2024-0799 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more