Veeam Urges Updates After Discovering Critical Vulnerability

Share:

The vulnerability affects certain versions of the Veeam Service Provider Console that can only be fixed by updating with the latest patch.

Data protection vendor Veeam released an update to address a critical vulnerability affecting the Veeam Service Provider Console (VSPC) that, if exploited, could lead to remote code execution (RCE).

Tracked as CVE-2024-42448 with a CVSS score of 9.9, the vulnerability was discovered by Veeam during internal testing. 

Veeam found another vulnerability in the process, CVE-2024-42449, with a high CVSS score of 7.1, which could leak an NTLM hash of the VSPC server service account and delete files off the machine.

Both of the vulnerabilities affect VSPC 8.1.0.21377 and all earlier versions of 7 and 8 builds.

“These service providers often trust their third-party vendor tools to manage client data and ensure business continuity,” Elad Luz, head of research as Oasis Security, wrote in an emailed statement to Dark Reading. “When these vendors, like Veeam, have vulnerabilities that allow remote code execution, it exposes critical backup infrastructure to potential exploitation. In industries where data security is paramount, such as finance, healthcare, and legal services, the risk is amplified as these sectors hold sensitive data that is attractive to cybercriminals.”

As there are no mitigations available for these vulnerabilities, Veeam recommends users of the supported versions of VSPC update to the latest cumulative patch.

Kristina Beek

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:25 pm, Jan 23, 2025
weather icon 6°C
L: 5° | H: 6°
overcast clouds
Humidity: 84 %
Pressure: 1003 mb
Wind: 6 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 88%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:51 am
Sunset: 4:33 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
5° | 6°°C 1 mm 100% 24 mph 87 % 1002 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
4° | 6°°C 1 mm 100% 9 mph 87 % 1010 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
3° | 8°°C 1 mm 100% 20 mph 91 % 1010 mb 0 mm/h
Mon Jan 27 9:00 pm
weather icon
5° | 8°°C 1 mm 100% 18 mph 91 % 988 mb 0 mm/h
Tue Jan 28 9:00 pm
weather icon
5° | 8°°C 1 mm 100% 23 mph 91 % 998 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 10 mph 84 % 1002 mb 0 mm/h
Tomorrow 3:00 am
weather icon
7° | 10°°C 0.75 mm 75% 21 mph 87 % 1000 mb 0 mm/h
Tomorrow 6:00 am
weather icon
8° | 10°°C 1 mm 100% 24 mph 86 % 995 mb 0 mm/h
Tomorrow 9:00 am
weather icon
11° | 11°°C 1 mm 100% 16 mph 79 % 993 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
9° | 9°°C 0.77 mm 77% 17 mph 61 % 997 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
8° | 8°°C 0 mm 0% 13 mph 51 % 999 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 8 mph 56 % 1001 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 6°°C 0 mm 0% 6 mph 65 % 1001 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,401.34
0.75%
Ethereum(ETH)
€3,201.82
3.00%
XRP(XRP)
€3.01
-0.81%
Tether(USDT)
€0.96
0.05%
Solana(SOL)
€244.23
-0.98%
Dogecoin(DOGE)
€0.340060
-1.68%
USDC(USDC)
€0.96
-0.01%
Shiba Inu(SHIB)
€0.000019
0.03%
Pepe(PEPE)
€0.000014
0.66%
Peanut the Squirrel(PNUT)
€0.333452
-4.27%
Scroll to Top