Veeam Unveils Security Patches to Address 18 Flaws, Including 5 Critical Weaknesses

Sep 05, 2024Ravie LakshmananThreat Prevention / Software Security

Veeam has issued deployed security patches to fix a total of 18 vulnerabilities in its software products, which also include five critical flaws that might allow for re

Veeam Releases Security Updates to Fix 18 Flaws, Including 5 Critical Issues

Sep 05, 2024Ravie LakshmananThreat Prevention / Software Security

Veeam has issued deployed security patches to fix a total of 18 vulnerabilities in its software products, which also include five critical flaws that might allow for remote code execution.

Here are the details of the vulnerabilities –

  • CVE-2024-40711 (CVSS score: 9.8) – An exploit in Veeam Backup & Replication that opens the door to unauthenticated remote code execution.
  • CVE-2024-42024 (CVSS score: 9.1) – A vulnerability in Veeam ONE that grants an attacker possessing the Agent service account credentials the ability to execute code remotely on the underlying machine
  • CVE-2024-42019 (CVSS score: 9.0) – A security hole in Veeam ONE that allows an intruder to obtain the NTLM hash of the Veeam Reporter Service service account
  • CVE-2024-38650 (CVSS score: 9.9) – An issue in Veeam Service Provider Console (VPSC) that permits a low-privileged perpetrator to retrieve the NTLM hash of the service account on the server
  • CVE-2024-39714 (CVSS score: 9.9) – A vulnerability in VPSC that empowers a low-level user to upload arbitrary files to the server, hence leading to remote code execution on the server

Moreover, the security updates released in September 2024 also tackle 13 additional significant weaknesses that could potentially enable privilege escalation, bypass multi-factor authentication (MFA), and execute code with elevated permissions.

All the vulnerabilities have been fixed in the following versions –

  • Veeam Backup & Replication 12.2 (build 12.2.0.334)
  • Veeam Agent for Linux 6.2 (build 6.2.0.101)
  • Veeam ONE v12.2 (build 12.2.0.4093)
  • Veeam Service Provider Console v8.1 (build 8.1.0.21377)
  • Veeam Backup for Nutanix AHV Plug-In v12.6.0.632
  • Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization Plug-In v12.5.0.299

Given the vulnerabilities in Veeam’s software, users are increasingly becoming a valuable target for malicious actors to deploy ransomware. It is recommended that users update to the latest version promptly to mitigate potential risks.

Interested in this article? Follow us on Twitter and LinkedIn for more exclusive content.

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.