PT-2024-6576 · Veeam · Veeam Backup & Replication+1

Yashar Shahinzadeh

·

Published

2024-05-21

·

Updated

2024-09-19

·

CVE-2024-29851

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Veeam Backup Enterprise Manager (affected versions not specified)
Description: The issue allows high-privileged users to steal the NTLM hash of the Enterprise manager service account. This is related to insufficient access control in Veeam Backup & Replication, which can be exploited by a remote attacker to gain unauthorized access to the NTLM hash. The exploitation is possible if the service account is not the default Local System account.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-07721
CVE-2024-29851

Affected Products

Veeam Backup & Replication
Veeam Backup Enterprise Manager