CVE-2024-33671: Veritas Backup Exec

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files.

Affected products

  • Veritas Backup Exec: from 21.0, before 23.0 (fixed in 23.0)

Published 2024-04-26. Last modified 2026-06-17.