Veeam drängt auf Updates nach Entdeckung einer kritischen Sicherheitslücke

Teilen:

The vulnerability affects certain versions of the Veeam Service Provider Console that can only be fixed by updating with the latest patch.

Data protection vendor Veeam released an update to address a critical vulnerability affecting the Veeam Service Provider Console (VSPC) that, if exploited, could lead to remote code execution (RCE).

Tracked as CVE-2024-42448 with a CVSS score of 9.9, the vulnerability was discovered by Veeam during internal testing. 

Veeam found another vulnerability in the process, CVE-2024-42449, with a high CVSS score of 7.1, which could leak an NTLM hash of the VSPC server service account and delete files off the machine.

Both of the vulnerabilities affect VSPC 8.1.0.21377 and all earlier versions of 7 and 8 builds.

“These service providers often trust their third-party vendor tools to manage client data and ensure business continuity,” Elad Luz, head of research as Oasis Security, wrote in an emailed statement to Dark Reading. “When these vendors, like Veeam, have vulnerabilities that allow remote code execution, it exposes critical backup infrastructure to potential exploitation. In industries where data security is paramount, such as finance, healthcare, and legal services, the risk is amplified as these sectors hold sensitive data that is attractive to cybercriminals.”

As there are no mitigations available for these vulnerabilities, Veeam recommends users of the supported versions of VSPC update to the latest cumulative patch.

Kristina Beek

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:20 pm, Juli 5, 2025
Wetter-Symbol 19°C
L: 18° | H: 20°
broken clouds
Luftfeuchtigkeit: 79 %
Druck: 1010 mb
Wind: 8 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:50 am
Sonnenuntergang: 9:19 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
18° | 20°°C 1 mm 100% 11 mph 85 % 1011 mb 0 mm/h
Mo. Juli 07 10:00 pm
Wetter-Symbol
13° | 20°°C 1 mm 100% 13 mph 92 % 1015 mb 0 mm/h
Di. Juli 08 10:00 pm
Wetter-Symbol
13° | 24°°C 0 mm 0% 11 mph 78 % 1020 mb 0 mm/h
Mi. Juli 09 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 7 mph 67 % 1022 mb 0 mm/h
Do. Juli 10 10:00 pm
Wetter-Symbol
18° | 30°°C 0 mm 0% 5 mph 55 % 1023 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 8 mph 79 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 6 mph 84 % 1009 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 7 mph 80 % 1006 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
19° | 19°°C 1 mm 100% 7 mph 85 % 1005 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
19° | 19°°C 1 mm 100% 9 mph 79 % 1005 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
19° | 19°°C 1 mm 100% 10 mph 77 % 1005 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
21° | 21°°C 1 mm 100% 11 mph 53 % 1005 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 18°°C 0.44 mm 44% 9 mph 60 % 1007 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,783.68
0.04%
Ethereum(ETH)
€2,135.41
0.41%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.88
-0.35%
Solana(SOL)
€125.02
-0.13%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.139306
0.50%
Shiba Inu(SHIB)
€0.000009
0.34%
Pepe(PEPE)
€0.000008
0.47%
Nach oben scrollen