Cyberattack News

Veeam Software Vulnerabilities Let Attackers Trigger Remote Code Execution

Veeam Software, a leading backup, recovery, and data management solutions provider, has announced the discovery and remedy of several critical and high-severity vulnerabilities across multiple products.

These vulnerabilities were identified during internal testing and through external reports, highlighting potential risks for users of Veeam Backup & Replication, Veeam ONE, Veeam Agent for Linux, Veeam Service Provider Console, and other Veeam products.

Key Vulnerabilities and Their Impacts

CVE-2024-40711 is a critical vulnerability that allows unauthenticated remote code execution (RCE) and was reported by Florian Hauser of CODE WHITE GmbH, with a CVSS score of 9.8.

CVE-2024-40713 and CVE-2024-40710 are high-severity vulnerabilities, enabling low-privileged users to alter Multi-Factor Authentication (MFA) settings and execute remote code, respectively.

Additionally, CVE-2024-39718 allows low-privileged users to remove files remotely, carrying a CVSS score of 8.1. Other vulnerabilities include issues with TLS certificate validation and local privilege escalation.

    1. Veeam Agent for LinuxCVE-2024-40709: A high-severity vulnerability allowing local privilege escalation to root level, reported via HackerOne.
    2. Veeam ONECVE-2024-42024 and CVE-2024-42019: Critical vulnerabilities allowing remote code execution and access to NTLM hashes, with CVSS scores of 9.1 and 9.0, respectively. Additional vulnerabilities include code execution with Administrator privileges and HTML injection.
    3. Veeam Service Provider ConsoleCVE-2024-38650 and CVE-2024-39714: Critical vulnerabilities allowing access to NTLM hashes and remote code execution through arbitrary file uploads, both with a CVSS score of 9.9.
    4. Veeam Backup for Nutanix AHV and Other Plug-InsCVE-2024-40718: A high-severity SSRF vulnerability allowing local privilege escalation.

    Solutions and Updates

    Veeam has addressed these vulnerabilities in the latest software updates, urging all users to upgrade to the following versions:

    • Veeam Backup & Replication: Version 12.2 (build 12.2.0.334)
    • Veeam Agent for Linux: Version 6.2 (build 6.2.0.101)
    • Veeam ONE: Version 12.2 (build 12.2.0.4093)
    • Veeam Service Provider Console: Version 8.1 (build 8.1.0.21377)
    • Veeam Backup for Nutanix AHV and Other Plug-Ins: Latest versions included with Veeam Backup & Replication 12.2

    Users are strongly advised to update to the latest versions to mitigate potential security risks. Veeam continues to prioritize security and encourages customers to remain vigilant and proactive in applying updates.

    Download Free Incident Response Plan Template for Your Security Team – Free Download

    Balaji N

    BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

    Recent Posts

    China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

    APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…

    2 hours ago

    Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

    The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

    2 hours ago

    Critical Grafana Vulnerability Let Attackers Escalate Privilege

    Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

    2 hours ago

    Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

    A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

    3 hours ago

    Windows 11 to Hide BSOD Crash Errors on Public Displays

    Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

    4 hours ago

    SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

    SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

    7 hours ago