CVE-2024-13976: Commvault For Windows
High severity, CVSS 8.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.
Affected products
- Commvault Commvault For Windows: from 11.20.0, before 11.20.202 (fixed in 11.20.202); from 11.28.0, before 11.28.124 (fixed in 11.28.124); from 11.32.0, before 11.32.65 (fixed in 11.32.65); from 11.34.0, before 11.34.37 (fixed in 11.34.37); from 11.36.0, before 11.36.15 (fixed in 11.36.15)
Published 2025-07-25. Last modified 2026-06-17.