CVE-2007-2360: Medium severity Symantec BackupExec System Recovery vulnerability
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2360?
CVE-2007-2360 has been rated as a moderate severity vulnerability due to the potential for local users to access sensitive information.
How do I fix CVE-2007-2360?
To fix CVE-2007-2360, ensure that you update to the latest versions of affected Symantec products released after April 26, 2007.
Which products are affected by CVE-2007-2360?
CVE-2007-2360 affects several Symantec products including Norton Ghost, Norton Save and Recovery, LiveState Recovery, and Backup Exec System Recovery.
Can local users exploit CVE-2007-2360?
Yes, local users can exploit CVE-2007-2360 to obtain encrypted network share credentials, posing a security risk.
What type of vulnerability is CVE-2007-2360?
CVE-2007-2360 is a credential management vulnerability that can lead to unauthorized access to sensitive information.