
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in Veritas Desktop and Laptop Option (DLO) before 9.4. On start-up, it loads the OpenSSL library from /ReleaseX64/ssl. This library attempts to load the /ReleaseX64/ssl/openssl.cnf configuration file, which does not exist. The vulnerability was discovered in December 2020 and assigned CVE-2020-36165 with a CVSS v3.1 Base Score of 9.3, indicating Critical severity. The issue affects DLO server and client installations across versions 9.3.3, 9.3.2, 9.3.1, 9.3, 9.2, 9.1, 9.0.1, and 9.0, with earlier unsupported versions potentially affected as well (Veritas Advisory).
By default, on Windows systems, users can create directories under C:. A low privileged user can create a C:/ReleaseX64/ssl/openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. The vulnerability has been assigned a CVSS vector of AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating local access, low complexity, no privileges required, no user interaction needed, and high impact across confidentiality, integrity, and availability (Veritas Advisory).
This vulnerability gives the attacker administrator access on the system, allowing them to access all data and installed applications by default. The critical severity rating indicates the potential for complete system compromise through privilege escalation from a low-privileged user account to SYSTEM level access (Veritas Advisory).
The vulnerability can be exploited by any low-privileged user on the Windows system without requiring any privileges in DLO. The attack requires local access to the system but needs no special privileges or user interaction to execute, making it relatively straightforward to exploit (Veritas Advisory).
For immediate mitigation without applying the patch, administrators can create the directory '\usr\local\ssl' under the root of all drives and set the ACL on the directory to deny write access to all other users. This prevents attackers from installing a malicious OpenSSL engine. For a permanent fix, customers under a current maintenance contract can download and install Veritas Desktop and Laptop Option version 9.5 (Veritas Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."