Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject malicious code that would execute with elevated LocalSystem privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veritas
Veritas netbackup |
|
| Vendors & Products |
Veritas
Veritas netbackup |
Mon, 02 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 01 Feb 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject malicious code that would execute with elevated LocalSystem privileges. | |
| Title | NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-01T14:38:27.147Z
Updated: 2026-02-02T19:05:01.646Z
Reserved: 2026-01-28T18:18:30.525Z
Link: CVE-2020-37045
Updated: 2026-02-02T19:04:52.641Z
Status : Awaiting Analysis
Published: 2026-02-01T15:16:03.563
Modified: 2026-02-03T16:44:36.630
Link: CVE-2020-37045
No data.