Attack Code Posted for CA BrightStor Flaw

執筆者
Ryan Naraine
Ryan Naraine
Published: Mar 18, 2008
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Hackers have posted proof-of-concept code that could be used to launch code execution attacks against businesses using the CA BrightStor ARCserve Backup software product.
eWEEK has confirmed that the code, posted at Milw0rm.com, exploits an unpatched ActiveX vulnerability in CA BrightStor ARCserve Backup to launch client-side attacks on laptop and desktop computers.
The attack code was successfully tested on CA BrightStor ARCserve Backup r11.5 in tandem with Internet Explorer 6 (Windows XP Service Pack 2).
According to virus trackers in Symantec’s DeepSight threat management system, there is a stack-based buffer overflow in the ListCtrl.ocx object. “An attacker may be able to corrupt structured exception handlers on the stack, thereby allowing arbitrary code to run. This issue can be triggered by passing a buffer to the ‘AddColumn()’ method,” according to DeepSight analyst Aaron Adams.

Hackers are looking to steal online gaming passwords. Read more here.

The current public exploit contains a payload that executes “calc.exe” (calculator) only, but Adams said that trivial modification of the code could allow an arbitrary payload, such as one to bind a shell to a TCP port. A more malicious payload could be included without affecting the exploit’s reliability, he said.
In the absence of a patch from CA, affected users are urged to set the kill bit on the affected CLSID (BF6EFFF3-4558-4C4C-ADAF-A87891C5F3A3) for workstations or terminal server computers that have the BrightStor ARCserve Backup software installed.
Instructions for disabling vulnerable ActiveX controls can be found in this Microsoft Knowledge Base article.
Symantec DeepSight also recommends:

  • Browsing the Web with the least privileges possible.
  • Disabling active content where possible.
  • Configuring operating systems to run with all available security mechanisms (such as DEP) enabled to hamper an attacker’s ability to successfully leverage the vulnerability.

Serious ActiveX vulnerabilities have recently been disclosed in several widely deployed software applications, including RealPlayer’s RealNetworks media player and image uploaders used by MySpace and Facebook.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。