Veeam Service Provider RCE-Schwachstelle ermöglicht Angreifern die Ausführung von beliebigem Code

Teilen:

Veeam, a leading provider of backup and disaster recovery solutions, has disclosed two significant vulnerabilities affecting its Service Provider Console (VSPC), including a critical remote code execution (RCE) flaw.

The vulnerabilities discovered during internal testing impact VSPC version 8.1.0.21377 and all earlier versions, including builds 8 and 7.

The most severe vulnerability tracked as CVE-2024-42448, has been assigned a critical CVSS v3.1 score of 9.9. This flaw allows attackers to execute arbitrary code on unpatched VSPC servers from the management agent machine, provided the agent is authorized on the server.

The potential for remote code execution poses a significant threat to the security and integrity of affected systems.

Alongside the critical RCE flaw, Veeam also patched a high-severity vulnerability (CVE-2024-42449) with a CVSS v3.1 score of 7.1. This security issue enables attackers to steal the NTLM hash of the VSPC server service account and potentially delete files on the VSPC server.

Like the RCE vulnerability, this flaw can only be exploited if the management agent is authorized on the targeted server.

Kostenloses Webinar über Best Practices für API-Schwachstellen und Penetrationstests: Kostenlose Registrierung

Affected Products and Versions

The vulnerabilities impact Veeam Service Provider Console 8.1.0.21377 and all earlier versions of builds 8 and 7. While unsupported product versions were not tested, Veeam warns that they should be considered vulnerable and urges users to upgrade.

Veeam has released security updates to address these vulnerabilities. The company strongly encourages service providers using supported versions of VSPC (versions 7 & 8) to update to the latest cumulative patch immediately. For those using unsupported versions, upgrading to the latest version of the Veeam Service Provider Console is crucial.

It’s important to note that no mitigation method is available for these vulnerabilities. The only effective remedy is to upgrade to the patched version, Veeam Service Provider Console 8.1.0.21999.

The discovery of these vulnerabilities underscores the critical importance of timely patching and updating in maintaining cybersecurity. Recent incidents involving the exploitation of Veeam vulnerabilities, such as the use of CVE-2024-40711 in Frag, Akira, and Fog ransomware attacks, highlight the urgency of addressing these security flaws.

Given Veeam’s extensive customer base, which includes over 550,000 customers worldwide and a significant portion of Global 2,000 and Fortune 500 companies, the potential impact of these vulnerabilities is substantial.

Service providers and enterprises using VSPC are strongly advised to take immediate action to protect their systems and data.

Organizations can promptly apply the available security updates to safeguard their backup and disaster recovery infrastructure against potentially exploiting these critical vulnerabilities.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:50 pm, März 16, 2025
Wetter-Symbol 8°C
L: 7° | H: 9°
wenige Wolken
Luftfeuchtigkeit: 57 %
Druck: 1025 mb
Wind: 10 mph ENE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:12 am
Sonnenuntergang: 6:06 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 9°°C 0 mm 0% 11 mph 77 % 1027 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 10 mph 89 % 1029 mb 0 mm/h
Di. März 18 9:00 pm
Wetter-Symbol
4° | 10°°C 0 mm 0% 12 mph 78 % 1027 mb 0 mm/h
Mi. März 19 9:00 pm
Wetter-Symbol
3° | 15°°C 0 mm 0% 7 mph 79 % 1022 mb 0 mm/h
Do. März 20 9:00 pm
Wetter-Symbol
8° | 14°°C 0 mm 0% 7 mph 78 % 1021 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
9° | 10°°C 0 mm 0% 11 mph 52 % 1025 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 8 mph 60 % 1025 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 77 % 1027 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 6 mph 84 % 1027 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 7 mph 89 % 1027 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 7 mph 81 % 1028 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 7 mph 66 % 1029 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 8 mph 52 % 1028 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€75,754.17
-1.81%
Ethereum(ETH)
€1,724.34
-2.40%
Fesseln(USDT)
€0.92
-0.02%
XRP(XRP)
€2.12
-4.76%
Solana(SOL)
€119.30
-2.97%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.154230
-3.68%
Shiba Inu(SHIB)
€0.000012
-0.11%
Pepe(PEPE)
€0.000006
-5.06%
Peanut das Eichhörnchen(PNUT)
€0.189019
20.47%
Nach oben scrollen