
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-34523 is a heap-based buffer overflow vulnerability in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). The flaw results from improper bounds checking when processing attacker-controlled input, allowing an unauthenticated remote attacker to corrupt heap memory, potentially causing denial of service or arbitrary code execution. It affects all Arcserve UDP versions prior to 10.2, including versions 7.x and earlier (unsupported) and versions 8.0 through 10.1 (supported but requiring patching). The vulnerability was published on August 27, 2025, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, Arcserve Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), stemming from insufficient bounds checking in the network-facing input handling routines of Arcserve UDP. An attacker can send specially crafted network data to the vulnerable service without authentication, triggering heap memory corruption in the affected process. This vulnerability is similar in nature to CVE-2025-34522 but affects a distinct code path or component. No user interaction is required, and exploitation occurs entirely in the context of the vulnerable process (Feedly, Arcserve Advisory).
Successful exploitation can result in full compromise of the affected system's confidentiality, integrity, and availability. An unauthenticated remote attacker may execute arbitrary code in the context of the vulnerable Arcserve UDP process, potentially enabling lateral movement within the network, exfiltration of backup data, or disruption of backup and recovery operations. At minimum, the vulnerability can be leveraged to cause a denial of service by corrupting heap memory (Feedly).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The vulnerability is remotely exploitable without authentication and requires no user interaction, making it highly attractive for threat actors if a working exploit is developed. The EPSS score is approximately 0.74%, indicating a currently low but non-negligible probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Arcserve has released UDP version 10.2, which includes the necessary patches and requires no further action. For installations running versions 8.0 through 10.1, administrators should apply the vendor-provided patches or upgrade to version 10.2. Versions 7.x and earlier are unsupported and must be upgraded to version 10.2 to remediate the issue. As interim mitigations, organizations should implement network segmentation to restrict access to Arcserve UDP management interfaces, monitor network traffic for anomalous activity targeting UDP service ports, and consider temporarily isolating unpatched systems from untrusted networks (Arcserve Advisory, Feedly).
The vulnerability received coverage from threat intelligence aggregators and security community platforms shortly after its August 27, 2025 disclosure, including posts on Infosec.Exchange and Bluesky by security researchers (Infosec.Exchange, Bluesky). runZero published a blog post covering the Arcserve UDP vulnerabilities, highlighting the risk to organizations using the backup software (runZero Blog). The vulnerability was also included in a CISA weekly vulnerability summary for the week of August 25, 2025 (Red Packet Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."