Veritas has discovered that the Veritas System Recovery folder is vulnerable to attackers running as low privileged users. See CVE-2023-28047 for more details. Existing System Recovery customers who are running in low privilege user mode must execute the script available from Veritas Download Center. This script applies to all previous versions of System Recovery.





Note 1: In the event of uninstallation, repair or upgrade of the product, the changes made will be reverted.
Note 2: Restoring the volume where Veritas System Recovery log resides or the machine, to point in time when vulnerability fix was not applied, will revert the current changes. Customers should re-run the script in such case after restore of volume or machine.
Note 3: This script will also generate "Permissions.txt" file in the same path where the script is running. The text file will contain the permissions for Veritas System Recovery folder before and after the script has run.
System Recovery Security Hotfix 860045 Script Execution Instructions