We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized access or lateral movement within the backup infrastructure. The issue has been resolved in versions 11.32.60, 11.34.34, and 11.36.8.
Reserved 2025-07-23 | Published 2025-07-25 | Updated 2025-07-25 | Assigner VulnCheckCWE-269 Improper Privilege Management
Commvault
documentation.commvault.com/...yadvisories/CV_2024_09_1.html
www.vulncheck.com/...ult-for-windows-access-nodes-compromise
Support options