CVE-2020-36160
Veritas System Recovery vulnerability analysis and mitigation

Overview

CVE-2020-36160 is a critical vulnerability discovered in Veritas System Recovery (VSR) affecting versions prior to 21.2. The vulnerability was disclosed on January 5, 2021. The issue affects Windows versions of VSR including 21.1, 21, 18.0.4, 18.0.3, 18.0.2, 18.0.1, 18.0, 16.0.2, 16.0.1 and 16, while non-Windows platforms are not affected (Vendor Advisory).

Technical details

The vulnerability occurs when VSR loads the OpenSSL library from \usr\local\ssl on startup. The library attempts to load a configuration file from \usr\local\ssl\openssl.cnf, which does not exist by default. Since Windows systems allow users to create directories under C:, a low-privileged user can create a malicious OpenSSL configuration file at C:\usr\local\ssl\openssl.cnf. The vulnerability has been assigned a CVSS v3.1 Base Score of 9.3 (CRITICAL) with vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (Vendor Advisory).

Impact

When successfully exploited, this vulnerability allows attackers to execute arbitrary code with SYSTEM privileges when the service starts. This grants the attacker administrator access to the system, enabling access to all data and installed applications. If the compromised system is an Active Directory domain controller, the impact extends to the entire domain (Vendor Advisory).

Exploitability

The vulnerability can be exploited by a low-privileged user on the Windows system without requiring any privileges in VSR. The attack involves creating a malicious OpenSSL configuration file in a specific location that gets loaded during service startup (Vendor Advisory).

Mitigation and workarounds

The primary remediation is to upgrade to Veritas System Recovery (VSR) 21.2 or later. For customers unable to upgrade immediately, a workaround exists: use an administrator account to create the directory '\usr\local\ssl' under the root of all drives and set the ACL on the directory to deny write access to all other users. This prevents attackers from installing a malicious OpenSSL engine (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related Veritas System Recovery vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-36160HIGH8.8
  • Veritas System Recovery logoVeritas System Recovery
  • cpe:2.3:a:veritas:system_recovery
NoYesJan 06, 2021
CVE-2024-35204HIGH8.4
  • Veritas System Recovery logoVeritas System Recovery
  • cpe:2.3:a:veritas:system_recovery
NoYesMay 14, 2024
CVE-2017-7444HIGH7.8
  • Veritas System Recovery logoVeritas System Recovery
  • cpe:2.3:a:veritas:system_recovery
NoYesApr 05, 2017
CVE-2022-41320MEDIUM6.5
  • Veritas System Recovery logoVeritas System Recovery
  • cpe:2.3:a:veritas:system_recovery
NoYesSep 23, 2022
CVE-2022-26778MEDIUM6.5
  • Veritas System Recovery logoVeritas System Recovery
  • cpe:2.3:a:veritas:system_recovery
NoYesMar 10, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management