Executive brief
Arcserve Unified Data Protection (UDP) is a backup and disaster recovery solution used to protect business data across various environments. A critical security flaw in its network communication component allows an unauthenticated attacker to remotely crash the service or potentially take full control of the backup server. This could lead to significant operational downtime, loss of backup integrity, or unauthorized access to sensitive corporate data.
Technical details
A heap-based buffer overflow (CWE-122) exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). The vulnerability is caused by improper bounds checking when processing attacker-controlled data sent over the network. A remote, unauthenticated attacker can exploit this by sending specially crafted packets to the vulnerable service, leading to heap memory corruption. Successful exploitation can result in a denial of service (DoS) or arbitrary code execution in the context of the vulnerable process. The issue is resolved in version 10.2; users on versions 8.0 through 10.1 should apply available patches or upgrade.
Affected products
- Arcserve Unified Data Protection (UDP) All versions prior to 10.2
Timeline
- 2025-08-27: disclosed
- 2025-08-27: advisory