A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.
History

Fri, 25 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Jul 2025 16:00:00 +0000

Type Values Removed Values Added
Description A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.
Title Commvault 11.20.0 - 11.36.0 Windows Maintenance Installer DLL Injection
Weaknesses CWE-427
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-07-25T15:50:17.950Z

Updated: 2025-07-25T17:49:35.606Z

Reserved: 2025-07-23T20:30:07.057Z

Link: CVE-2024-13976

cve-icon Vulnrichment

Updated: 2025-07-25T17:49:30.981Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-25T16:15:27.690

Modified: 2025-07-29T14:14:55.157

Link: CVE-2024-13976

cve-icon Redhat

No data.