CVE-2024-13976
Published: Jul 25, 2025
Modified: Nov 22, 2025
Description
A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.
| Vendor | Product | Versions |
|---|---|---|
Commvault | Commvault for Windows | affected 11.20.0 - < 11.20.202affected 11.28.0 - < 11.28.124affected 11.32.0 - < 11.32.65affected 11.34.0 - < 11.34.37affected 11.36.0 - < 11.36.15 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now