Cyberattack News

Veeam Software Vulnerabilities Let Attackers Trigger Remote Code Execution

Veeam Software, a leading backup, recovery, and data management solutions provider, has announced the discovery and remedy of several critical and high-severity vulnerabilities across multiple products.

These vulnerabilities were identified during internal testing and through external reports, highlighting potential risks for users of Veeam Backup & Replication, Veeam ONE, Veeam Agent for Linux, Veeam Service Provider Console, and other Veeam products.

Key Vulnerabilities and Their Impacts

CVE-2024-40711 is a critical vulnerability that allows unauthenticated remote code execution (RCE) and was reported by Florian Hauser of CODE WHITE GmbH, with a CVSS score of 9.8.

CVE-2024-40713 and CVE-2024-40710 are high-severity vulnerabilities, enabling low-privileged users to alter Multi-Factor Authentication (MFA) settings and execute remote code, respectively.

Additionally, CVE-2024-39718 allows low-privileged users to remove files remotely, carrying a CVSS score of 8.1. Other vulnerabilities include issues with TLS certificate validation and local privilege escalation.

    1. Veeam Agent for LinuxCVE-2024-40709: A high-severity vulnerability allowing local privilege escalation to root level, reported via HackerOne.
    2. Veeam ONECVE-2024-42024 and CVE-2024-42019: Critical vulnerabilities allowing remote code execution and access to NTLM hashes, with CVSS scores of 9.1 and 9.0, respectively. Additional vulnerabilities include code execution with Administrator privileges and HTML injection.
    3. Veeam Service Provider ConsoleCVE-2024-38650 and CVE-2024-39714: Critical vulnerabilities allowing access to NTLM hashes and remote code execution through arbitrary file uploads, both with a CVSS score of 9.9.
    4. Veeam Backup for Nutanix AHV and Other Plug-InsCVE-2024-40718: A high-severity SSRF vulnerability allowing local privilege escalation.

    Solutions and Updates

    Veeam has addressed these vulnerabilities in the latest software updates, urging all users to upgrade to the following versions:

    • Veeam Backup & Replication: Version 12.2 (build 12.2.0.334)
    • Veeam Agent for Linux: Version 6.2 (build 6.2.0.101)
    • Veeam ONE: Version 12.2 (build 12.2.0.4093)
    • Veeam Service Provider Console: Version 8.1 (build 8.1.0.21377)
    • Veeam Backup for Nutanix AHV and Other Plug-Ins: Latest versions included with Veeam Backup & Replication 12.2

    Users are strongly advised to update to the latest versions to mitigate potential security risks. Veeam continues to prioritize security and encourages customers to remain vigilant and proactive in applying updates.

    Download Free Incident Response Plan Template for Your Security Team – Free Download

    Balaji N

    BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

    Recent Posts

    Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

    Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

    4 hours ago

    Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

    Hackers are making some phishing pages harder to track by changing the code delivered to…

    4 hours ago

    Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

    A cyber incident reportedly forced a British power plant to halt operations for about four…

    5 hours ago

    Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

    Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

    5 hours ago

    Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

    TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

    5 hours ago

    Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

    A fake student resume is being used to place a remote-access tool on researchers’ Windows…

    7 hours ago