External risk intelligence

Arcserve UDP Heap Overflow Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2025-34522

Arcserve UDP is backup software designed for internal network segments. While it is network-reachable and possesses interfaces that could be exposed, it is not intended to be a public-facing edge service. Reachability from the internet is generally a result of misconfiguration or administrative choice rather than standard deployment practice.

Remote Code Execution

Arcserve Udp

before 7.08.0 to before 10.27.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Arcserve Unified Data Protection (UDP), a data backup solution. The flaw allows unauthenticated attackers to potentially execute code on affected systems by sending specially crafted data. This presents a significant risk because it can be exploited without any prior access or credentials and could lead to a complete compromise of the system.

  • Input parsing flaw affects backup software.
  • Pre-authentication vulnerability poses high risk.
  • Confirm relevance and exposure for business continuity.

Attack Path

How an attacker could exploit the issue

An attacker can target Arcserve Unified Data Protection (UDP) by sending specially crafted data to the system. This data exploits a flaw in how the software handles input, leading to a buffer overflow. Successful exploitation can overwrite memory, potentially allowing an attacker to execute arbitrary code or cause the application to crash.

  • No authentication required to initiate.
  • Specially crafted input triggers overflow.
  • Potential for code execution or crash.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Arcserve Unified Data Protection (UDP) could allow an unauthenticated attacker to cause application crashes or potentially execute arbitrary code. Exploitation could occur when specially crafted input is sent to the target system, affecting the integrity and availability of the affected process.

  • System data and application integrity.
  • Sending crafted input to the system.
  • Application crash or code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that Arcserve Unified Data Protection (UDP) is typically used for internal backups, platform or infrastructure teams are likely responsible for managing its deployment and security. The immediate practical step is to inventory all UDP instances, confirm their reachability and criticality to business operations, and identify the specific application or system owner. Remediation planning should then be prioritized based on this risk assessment.

  • Platform or infrastructure teams own this issue.
  • Verify UDP instance inventory and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Arcserve Unified Data Protection (UDP)?

Arcserve UDP is a comprehensive data protection and backup software suite. Organizations use it to centralize data management, ensure business continuity, and secure critical information across physical, virtual, and cloud environments.

How does this heap-based buffer overflow work in CVE-2025-34522?

This vulnerability, classified as CWE-122, occurs when the software's input parsing logic fails to properly check the size of incoming data. By sending a specially crafted input, an attacker can write past the allocated memory buffer, potentially corrupting application behavior or executing unauthorized commands.

Do I need to be logged into Arcserve UDP to trigger this vulnerability?

No. The flaw exists in the input parsing process that occurs before any authentication checks. The system is vulnerable even if the attacker does not have valid credentials. Conversely, standard legitimate traffic that does not contain the specifically manipulated input structures will not trigger this memory error.

Why is this considered a risk for my Arcserve UDP instances?

While Halo Surface Signal notes that UDP is typically designed for internal network segments and is not meant to be public-facing, any instance reachable over the network is at risk. If your configuration allows access from untrusted zones, the lack of authentication makes this a high-priority concern for system integrity.

When should I prioritize updating my Arcserve UDP installation?

You should act immediately by auditing your environment to locate all running versions. If you are on version 10.1 or earlier, you must either apply the necessary patches or perform an upgrade to version 10.2, which contains the fix. If you are on unsupported versions 7.x or older, upgrading to 10.2 is mandatory to secure your system.

References