OSVDB ID: 86158

Title: EMC NetWorker Module for Microsoft Applications (NMM) Communication Channel Crafted Message Parsing Remote Code Execution

Info

Disclosure

Oct 10, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Oct 10, 2012

Description

EMC NetWorker Module for Microsoft Applications contains a flaw that is triggered when an error occurs in NMM clients during channel communication. With a specially crafted message, a remote attacker can potentially execute arbitrary code over TCP.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Unknown
Disclosure: Vendor Verified

Solution

Upgrade to version 2.3 build 122 or 2.4 build 375 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

EMC Corporation

NetWorker Module for Microsoft Applications

2.2.1
2.3
2.4

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/86158