CVE-2008-3703: Critical severity veritas storage foundation for oracle vulnerability
The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0, 5.0 RP1a, and 5.1 accepts NULL NTLMSSP authentication, which allows remote attackers to execute arbitrary code via requests to the service socket that create "snapshots schedules" registry values specifying future command execution. NOTE: this issue exists because of an incomplete fix for CVE-2007-2279.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3703?
CVE-2008-3703 has a medium severity rating due to its potential to allow remote code execution.
How do I fix CVE-2008-3703?
To fix CVE-2008-3703, update to the latest version of Symantec Veritas Storage Foundation that addresses this vulnerability.
What systems are affected by CVE-2008-3703?
CVE-2008-3703 affects Symantec Veritas Storage Foundation for Windows versions 5.0, 5.0 RP1a, and 5.1.
What type of vulnerability is CVE-2008-3703?
CVE-2008-3703 is a remote code execution vulnerability due to improper handling of authentication requests.
Can CVE-2008-3703 be exploited remotely?
Yes, CVE-2008-3703 can be exploited remotely by attackers sending specially crafted requests to the service socket.