CVE-2017-18044: OS Command Injection
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not properly validate the input of an incoming string before passing it to CreateProcess. As a result, a specially crafted message can inject commands that will be executed on the target operating system. Exploitation of this vulnerability does not require authentication and can lead to SYSTEM level privilege on any system running the cvd daemon. This is a different vulnerability than CVE-2017-3195.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18044?
CVE-2017-18044 is considered a high-severity vulnerability due to its potential for command injection.
How do I fix CVE-2017-18044?
To fix CVE-2017-18044, upgrade Commvault to version 11 SP6 or later, where the vulnerability is addressed.
Which versions of Commvault are affected by CVE-2017-18044?
CVE-2017-18044 affects Commvault versions 11.0 SP1 to 11.0 SP5.
What type of vulnerability is CVE-2017-18044?
CVE-2017-18044 is classified as a command injection vulnerability.
What can be exploited through CVE-2017-18044?
CVE-2017-18044 can be exploited to execute arbitrary commands on the host running the affected Commvault software.