Executive brief
IBM Storage Protect Client, a backup and data recovery solution, is vulnerable to a security flaw that could allow an attacker to take control of the system. By sending specially crafted data, a remote attacker could cause the software to crash or execute unauthorized commands. This could lead to a total loss of data confidentiality and system availability on affected Windows backup clients.
Technical details
IBM Storage Protect Client is vulnerable to a heap-based buffer overflow due to improper bounds checking during string copy operations. The vulnerability can be triggered by a remote attacker who sends malicious input to the client, though the attack complexity is rated as high, suggesting specific timing or environmental conditions may be required. Successful exploitation allows the attacker to execute arbitrary code with the privileges of the client service or cause a denial-of-service (crash). The issue affects Windows platforms and has been addressed in version 8.2.1.2.
Affected products
- IBM Storage Protect Client 8.1.0.0 - 8.1.27.0, 8.1.27.1, 8.2.0.0 - 8.2.1.0
Timeline
- 2026-07-10: disclosed: Initial publication by IBM
- 2026-07-17: advisory: NVD publication date