cancel
Showing results for 
Search instead for 
Did you mean: 

Backup Exec Windows Agent Remote File Access Exploit (0day)

Christopher_Hoe
Not applicable
Don't see any discussion on this. Any patch or work arounds in sight?
9 REPLIES 9

641308656
Not applicable
Here's the Veritas tech note:-

http://support.veritas.com/docs/278434

But good luck following it, I'm getting my usual problems with Veritas BE10 patches :(

One server patched OK, a second server is giving the old "Wizard was interrupted" error an the patch fails.

Also trying to apply the RAWSx64 update from the one server that did patch gives the error "The upgrade patch cannot be installed by the windows installer service because the program to be upgraded may be missing"

It appears that although my servers are version 5520, the x64 agent is 5484, I can't apply the 5484 patch to the servers and the x64 agent .MSP file the 5520 patch installs won't fix the 5484 agents.

And the Veritas download search web page is giving an "index corrupt" error at the moment, so I can't look if there's a 5520 RAWSx64 agent available I can install and then patch

Thankfully port 10000 is blocked on our firewalls, so I suppose I'll have to wait until Veritas release proper full versions of BE10 and the x64 agent, instead of these damn patches that hardly ever seem to apply properly.

Every one else's patches work for me, but ever since upgrading from BE9 to BE10 I've hardly got a single Veritas patch to apply :(

Ortho_Lawton
Level 5
Now the Veritas download site is working again the only RAWSx64 agent I can find is version 5484.

There seems no way to apply the zero day vulnerability patch to this if you're running a 5520 server.

The RAWSx64 agent .MSP patch file dropped by the 5520 server patch won't apply to the 5484 x64 agent, and there seems no way to get a 5520 RAWSX64 agent so you can patch it, it doesn't come with the original 5520 server install files and it's not available for download - unless anyone can point me to a URL for it?

Thanks

Deepali_Badave
Level 6
Employee
Hello,

Are you facing a problem of Backup Exec Windows Agent Remote File Access Exploit?

Please elaborate your query to further troubleshoot this issue.


For information on the recent VERITAS Backup Exec security vulnerabilities, including links to the downloads for the necessary hotfixes, please refer to the following document:
Patch summary for Security Advisories VX05-001, VX05-002, VX05-003, VX05-005, VX05-006, VX05-007

http://seer.support.veritas.com/docs/277429.htm

NOTE : If we do not receive your reply within two business days, this post would be marked assumed answered and would be moved to answered questions pool.

Ortho_Lawton
Level 5
My problem is that the only version of the RAWSx64 agent available appears to be version 5484, which I'm using. However my backup server is running BE10 5520.

When I apply the hotfix at:- http://seer.support.veritas.com/docs/278465.htm
to my server It drops an .MSP file to patch the RAWSx64 agent version 5520, which doesn't seem to be available anywhere for download and it doesn't come with the full 5520 server install either.

What I want to know is either the procedure to patch the RAWSx64 version 5484 agent, if your server is running BE10 version 5520.
Or alternatively where I can download the RAWSx64 agent version 5520 that I can patch.

Thanks

Deepali_Badave
Level 6
Employee
Hello,

Please update us on this issue.

For information on the recent VERITAS Backup Exec security vulnerabilities, including links to the downloads for the necessary hotfixes, please refer to the following document:
Patch summary for Security Advisories VX05-001, VX05-002, VX05-003, VX05-005, VX05-006, VX05-007

http://seer.support.veritas.com/docs/277429.htm

NOTE : If we do not receive your reply within two business days, this post would be marked assumed answered and would be moved to answered questions pool.

Thanks,

Ortho_Lawton
Level 5
Thanks, I'd alrady noted that the 5520 x64 agent has NOW been put on your download site, so I was able to download that, install it and then patch with the original .MSP patch file.

Issue solved

tejashree_Bhate
Level 6
Hello,

Thanks for the update

As your issue is resolved please let us know if we can mark this this thread as assumed answered.

Note : If we do not receive your reply within two business days, this post would be marked ‘assumed answered’ and would be moved to ‘answered questions’ pool.


Thanks.

Ortho_Lawton
Level 5
Yes, thanks, please mark as answered

Renuka_-
Level 6
Employee
Hello,
Thank you for the update, this thread is herewith archived.
- Regards.