
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-34522 is a heap-based buffer overflow vulnerability in the input parsing logic of Arcserve Unified Data Protection (UDP). It can be triggered without authentication by sending specially crafted input to the target system, potentially leading to application crashes or remote code execution. All UDP versions prior to 10.2 are affected; versions 8.0 through 10.1 are supported and require patching, while versions 7.x and earlier are end-of-life and must be upgraded to 10.2. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (Feedly, Arcserve Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), arising from improper bounds checking in the input parsing logic of Arcserve UDP. An unauthenticated remote attacker can send specially crafted network input to trigger the overflow, overwriting heap memory in the context of the affected process. No user interaction is required, and the attack complexity is low, making it straightforward to exploit over the network. The flaw is also mapped to CAPEC-92 (Forced Integer Overflow), suggesting the overflow may be triggered via malformed integer values in the parsed input (Feedly, Arcserve Advisory).
Successful exploitation can result in remote code execution or application crashes, with high impact to confidentiality, integrity, and availability of the affected system. Because the vulnerability is pre-authentication and requires no user interaction, any network-accessible Arcserve UDP instance is at immediate risk of full system compromise. An attacker achieving code execution in the context of the UDP process could access sensitive backup data, disrupt backup and recovery operations, or use the compromised host as a pivot point for lateral movement within the environment (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.81%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. However, the pre-authentication, network-accessible nature of the flaw makes it a high-priority target if a public exploit becomes available.
Arcserve has released UDP version 10.2, which includes the necessary patches and requires no further action. For supported versions 8.0 through 10.1, administrators should apply the vendor-provided security patch or upgrade to version 10.2. Versions 7.x and earlier are unsupported and must be upgraded to version 10.2 to remediate the issue. As interim mitigations, organizations should isolate UDP systems from untrusted networks using firewall rules and network segmentation, and monitor for unauthorized access attempts (Arcserve Advisory, Feedly).
The vulnerability received coverage from security aggregators and threat intelligence platforms shortly after disclosure, including mentions on Mastodon/infosec.exchange and Bluesky by security researchers (infosec.exchange, Bluesky). runZero published a blog post covering the Arcserve UDP vulnerability, highlighting its risk to backup infrastructure (runZero Blog). No major vendor statements beyond the Arcserve advisory or notable researcher deep-dives have been publicly identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."