A buffer overflow vulnerability exists in the Tape Engine (tapeeng.exe) component of CA BrightStor ARCserve Backup 11.5 and earlier. The flaw is triggered by specially crafted RPC requests sent to TCP port 6502, which can cause a buffer overflow condition in tapeeng.exe, allowing for the execution of arbitrary code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting a stack buffer overflow vulnerability (CVE-2006-6076) in Computer Associates BrightStor ARCserve Backup Tape Engine (versions r11.1 and r11.5) on Windows. The exploit works by sending a specially crafted DCERPC request to the service, which listens by default on TCP port 6502. The module allows the attacker to execute arbitrary code with high privileges on the target system. The payload is customizable (up to 500 bytes, avoiding certain bad characters) and is delivered via a SEH-based buffer overflow. The exploit is operational and leverages Metasploit's payload and handler infrastructure. The only file present is a Ruby script structured as a standard Metasploit exploit module, and it does not contain detection or fake code. The main network endpoint is the DCERPC service on port 6502, and the exploit specifically targets the DCERPC interface with UUID 62b93df0-8b02-11ce-876c-00805f842837.
This repository contains a single Metasploit exploit module targeting a stack buffer overflow vulnerability (CVE-2006-6076) in Computer Associates BrightStor ARCserve Backup Tape Engine (versions r11.1 to r11.5) on Windows 2003. The exploit works by sending a specially crafted DCERPC request to the service listening on TCP port 6502, causing a buffer overflow and allowing arbitrary code execution. The module allows the attacker to select a payload (up to 500 bytes, avoiding certain bad characters) which will be executed with the privileges of the Tape Engine service. The exploit is operational and leverages the Metasploit framework's payload and handler infrastructure. The only file present is a Ruby script structured as a standard Metasploit module, with clear entry points and configuration for targeting the vulnerable service.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.