A format string flaw exists in EMC NetWorker. The librpc.dll library fails to properly sanitize format string specifiers (e.g., %s and %x). When parsing specially crafted data, a remote attacker can crash the service or possibly execute arbitrary code.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Third-party Verified,
Coordinated Disclosure
Solution
Upgrade to version 7.6.4.1 or 8.0.0.1 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.