Executive brief
Quest NetVault Backup is a data protection solution used to back up and recover corporate data across physical and virtual environments. A security vulnerability in how the software handles database queries allows a remote attacker to bypass security checks and execute unauthorized commands. This could lead to a complete takeover of the backup server, potentially resulting in the loss, theft, or encryption of sensitive backup data.
Technical details
A SQL injection vulnerability exists within the processing of NVBULibrarySlot JSON-RPC messages in Quest NetVault Backup. The root cause is a lack of proper validation of user-supplied strings before they are used to construct SQL queries. While the affected function technically requires authentication, the existing authentication mechanism can be bypassed, making the flaw accessible to unauthenticated remote attackers. Successful exploitation allows for arbitrary code execution in the security context of the NETWORK SERVICE account. The vulnerability was addressed in version 14.0.2.
Affected products
- Quest NetVault Backup 14.0.0.19
Timeline
- 2025-09-24: disclosed: Vulnerability reported to vendor
- 2026-06-24: patched: Coordinated public release of advisory and update