ZeroHour

CVE-2026-77092

Deserialization Privilege Escalation in Content Extractor

CVSS 4.0
7.3 high
EPSS
<1%p6
Published
()
Modified
AI analysis

Content Extractor contains a deserialization of untrusted data flaw (CWE-502) that affects privilege management, meaning crafted serialized input can subvert the product's privilege handling. The CVSS 4.0 vector indicates exploitation requires low privileges on the local system with no user interaction, but a high attack complexity and the presence of required preconditions (AT:P) make reliable exploitation harder to pull off. A successful attacker achieves high confidentiality, integrity, and availability impact on the vulnerable system — consistent with privilege escalation or code execution on that host — with no impact spreading to downstream systems. Users of Content Extractor running a version prior to the resolved maintenance release are affected; the advisory does not specify affected or fixed version numbers. There is no public proof of concept, the issue is not in CISA KEV, and EPSS puts exploitation probability at about 0.2% over 30 days, so no exploitation is currently known.

What to do: Update Content Extractor to the resolved maintenance release as directed by the vendor, and confirm the exact fixed version number with them since the advisory omits it. Until patched, restrict low-privileged local access to systems running Content Extractor and review where it deserializes externally supplied data. Prioritize patching hosts where untrusted users can reach the product, given the local attack vector.

Affected
Content Extractor
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.

Vendors
commvault
Products
commvault
Weakness
CWE-502
Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.