A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 25 Jul 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15. | |
Title | Commvault 11.20.0 - 11.36.0 Windows Maintenance Installer DLL Injection | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-25T15:50:17.950Z
Updated: 2025-07-25T17:49:35.606Z
Reserved: 2025-07-23T20:30:07.057Z
Link: CVE-2024-13976

Updated: 2025-07-25T17:49:30.981Z

Status : Awaiting Analysis
Published: 2025-07-25T16:15:27.690
Modified: 2025-07-29T14:14:55.157
Link: CVE-2024-13976

No data.