Vulnerability Description
A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.
Related Weaknesses (CWE)
References
- https://documentation.commvault.com/securityadvisories/CV_2024_09_2.html
- https://www.vulncheck.com/advisories/commvault-for-windows-maintenance-installer
FAQ
What is CVE-2024-13976?
CVE-2024-13976 is a documented vulnerability. A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit...
How severe is CVE-2024-13976?
CVSS scoring is not yet available for CVE-2024-13976. Check NVD for updates.
Is there a patch for CVE-2024-13976?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.