CVE-2005-1372: Medium severity Bakbone Netvault vulnerability
Published May 2, 2005
·Updated
nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.
Affected Software
2 affected components
Bakbone Netvault=7.3
Bakbone Netvault=7.1.1
Event History
May 2, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1372?
CVE-2005-1372 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2005-1372?
To mitigate CVE-2005-1372, upgrade to NetVault version 7.3 or later.
3
Who is affected by CVE-2005-1372?
CVE-2005-1372 affects local users of BakBone NetVault versions 7.1 and 7.1.1.
4
What causes CVE-2005-1372?
CVE-2005-1372 is caused by nvstatsmngr.exe failing to drop privileges before opening files.
5
Can remote attackers exploit CVE-2005-1372?
No, CVE-2005-1372 can only be exploited by local users.