CVE Database
/

CVE-2024-13976

Back to search

CVE-2024-13976

Published: Jul 25, 2025

Modified: Nov 22, 2025

PUBLISHED

Description

A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15.

VendorProductVersions

Commvault

Commvault for Windows

affected
11.20.0 - < 11.20.202
affected
11.28.0 - < 11.28.124
affected
11.32.0 - < 11.32.65
affected
11.34.0 - < 11.34.37
affected
11.36.0 - < 11.36.15

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now