CVE-2024-35204
Veritas System Recovery vulnerability analysis and mitigation

Overview

Veritas System Recovery versions prior to 23.3_Hotfix contain a high-severity vulnerability (CVE-2024-35204) related to incorrect permissions for the Veritas System Recovery folder. The vulnerability was discovered and disclosed on May 14, 2024, affecting multiple versions including 23.3, 23.2, 23.1, 23.0, 22.0, 21.3, 21.2, 21.1, and 21.0, as well as potentially earlier unsupported versions (Veritas Advisory).

Technical details

The vulnerability stems from the way Veritas System Recovery service handles logging information. When running, the service logs information into 'C:\ProgramData\Veritas\VERITAS SYSTEM RECOVERY\LOGS\Veritas System Recovery.log.txt' file with NT Authority\System permissions. The file is not exclusively opened or protected, allowing it to be deleted at any time. Additionally, the LOGS directory is modifiable by low-privileged Windows system users, enabling transformation into a directory junction and symbolic link. The vulnerability has been assigned a CVSS v3.1 Base Score of 8.4 (AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and is classified as CWE-272: Least Privilege Violation (Veritas Advisory).

Impact

The vulnerability allows attackers with low-privilege Windows system user access to create files in arbitrary locations within the filesystem, including protected directories such as C:\Windows, C:\Windows\System32, and C:\Program Files. This capability could be exploited to cause denial of service or tamper with important services, such as backup services, using a low-privilege user account (Security Online).

Exploitability

The vulnerability can be exploited by low-privileged users who have access to the system. The attack vector is local (AV:L), requiring low attack complexity (AC:L) with no privileges required (PR:N) and no user interaction (UI:N) (Veritas Advisory).

Mitigation and workarounds

Veritas has released Hotfix 860045 to address the vulnerability. Customers under a current maintenance contract who are running in low privilege user mode should download and execute the script available from the Veritas Download Center under the Updates section. The fix is included in version 23.3_Hotfix (Veritas Advisory).

Additional resources


SourceThis report was generated using AI

Related Veritas System Recovery vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-36160HIGH8.8
  • Veritas System Recovery logoVeritas System Recovery
  • cpe:2.3:a:veritas:system_recovery
NoYesJan 06, 2021
CVE-2024-35204HIGH8.4
  • Veritas System Recovery logoVeritas System Recovery
  • cpe:2.3:a:veritas:system_recovery
NoYesMay 14, 2024
CVE-2017-7444HIGH7.8
  • Veritas System Recovery logoVeritas System Recovery
  • cpe:2.3:a:veritas:system_recovery
NoYesApr 05, 2017
CVE-2022-41320MEDIUM6.5
  • Veritas System Recovery logoVeritas System Recovery
  • cpe:2.3:a:veritas:system_recovery
NoYesSep 23, 2022
CVE-2022-26778MEDIUM6.5
  • Veritas System Recovery logoVeritas System Recovery
  • cpe:2.3:a:veritas:system_recovery
NoYesMar 10, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management