In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker has write access to the directory from which the product is executed.
https://www.veritas.com/content/support/en_US/security/VTS17-001.html#Issue1