CVE-2025-34522
Arcserve Unified Data Protection vulnerability analysis and mitigation

Overview

CVE-2025-34522 is a heap-based buffer overflow vulnerability in the input parsing logic of Arcserve Unified Data Protection (UDP). It can be triggered without authentication by sending specially crafted input to the target system, potentially leading to application crashes or remote code execution. All UDP versions prior to 10.2 are affected; versions 8.0 through 10.1 are supported and require patching, while versions 7.x and earlier are end-of-life and must be upgraded to 10.2. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (Feedly, Arcserve Advisory).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), arising from improper bounds checking in the input parsing logic of Arcserve UDP. An unauthenticated remote attacker can send specially crafted network input to trigger the overflow, overwriting heap memory in the context of the affected process. No user interaction is required, and the attack complexity is low, making it straightforward to exploit over the network. The flaw is also mapped to CAPEC-92 (Forced Integer Overflow), suggesting the overflow may be triggered via malformed integer values in the parsed input (Feedly, Arcserve Advisory).

Impact

Successful exploitation can result in remote code execution or application crashes, with high impact to confidentiality, integrity, and availability of the affected system. Because the vulnerability is pre-authentication and requires no user interaction, any network-accessible Arcserve UDP instance is at immediate risk of full system compromise. An attacker achieving code execution in the context of the UDP process could access sensitive backup data, disrupt backup and recovery operations, or use the compromised host as a pivot point for lateral movement within the environment (Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.81%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. However, the pre-authentication, network-accessible nature of the flaw makes it a high-priority target if a public exploit becomes available.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Arcserve UDP instances (versions prior to 10.2) using network scanning tools such as Shodan, Censys, or Nmap targeting known Arcserve UDP service ports.
  2. Craft malicious input: Prepare a specially crafted network payload designed to trigger improper bounds checking in the UDP input parsing logic, potentially leveraging malformed integer values (per CAPEC-92) to cause a heap overflow.
  3. Send unauthenticated request: Transmit the crafted payload directly to the target Arcserve UDP service without requiring any credentials or prior authentication.
  4. Trigger heap overflow: The malformed input causes the application to overwrite heap memory beyond the allocated buffer, potentially corrupting control structures.
  5. Achieve code execution or crash: Depending on heap layout and exploit reliability, the attacker may achieve arbitrary remote code execution in the context of the UDP process, or cause a denial-of-service crash (Feedly, Arcserve Advisory).

Indicators of compromise

  • Network: Unexpected or malformed inbound connections to Arcserve UDP service ports from untrusted or external IP addresses; unusual spikes in connection attempts to UDP management interfaces.
  • Logs: Application crash logs or heap corruption error messages in Arcserve UDP service logs; repeated parsing errors or exceptions in the UDP input handling component.
  • Process: Unexpected child processes spawned by the Arcserve UDP service process; unusual outbound network connections initiated by the UDP service process.
  • File System: Unexpected new files, scripts, or executables written to directories accessible by the Arcserve UDP service account; modifications to Arcserve UDP configuration files.

Mitigation and workarounds

Arcserve has released UDP version 10.2, which includes the necessary patches and requires no further action. For supported versions 8.0 through 10.1, administrators should apply the vendor-provided security patch or upgrade to version 10.2. Versions 7.x and earlier are unsupported and must be upgraded to version 10.2 to remediate the issue. As interim mitigations, organizations should isolate UDP systems from untrusted networks using firewall rules and network segmentation, and monitor for unauthorized access attempts (Arcserve Advisory, Feedly).

Community reactions

The vulnerability received coverage from security aggregators and threat intelligence platforms shortly after disclosure, including mentions on Mastodon/infosec.exchange and Bluesky by security researchers (infosec.exchange, Bluesky). runZero published a blog post covering the Arcserve UDP vulnerability, highlighting its risk to backup infrastructure (runZero Blog). No major vendor statements beyond the Arcserve advisory or notable researcher deep-dives have been publicly identified at this time.

Additional resources


SourceThis report was generated using AI

Related Arcserve Unified Data Protection vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-34523CRITICAL9.2
  • Arcserve Unified Data Protection logoArcserve Unified Data Protection
  • cpe:2.3:a:arcserve:udp
NoYesAug 27, 2025
CVE-2025-34522CRITICAL9.2
  • Arcserve Unified Data Protection logoArcserve Unified Data Protection
  • cpe:2.3:a:arcserve:udp
NoYesAug 27, 2025
CVE-2025-34520HIGH7.7
  • Arcserve Unified Data Protection logoArcserve Unified Data Protection
  • cpe:2.3:a:arcserve:udp
NoYesAug 27, 2025
CVE-2024-0801HIGH7.5
  • Arcserve Unified Data Protection logoArcserve Unified Data Protection
  • cpe:2.3:a:arcserve:udp
NoNoMar 13, 2024
CVE-2025-34521MEDIUM4.8
  • Arcserve Unified Data Protection logoArcserve Unified Data Protection
  • cpe:2.3:a:arcserve:udp
NoYesAug 27, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management