PT-2024-9472 · Veeam · Veeam Backup & Replication

Sina Kheirkhah

·

Published

2024-08-02

·

Updated

2024-12-05

·

CVE-2024-42455

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Veeam Backup & Replication (affected versions not specified)
Description: The issue is related to insecure deserialization in Veeam Backup & Replication, allowing a low-privileged user to connect to remoting services and exploit this vulnerability by sending a serialized temporary file collection. This can enable an attacker to delete any file on the system with service account privileges. The vulnerability is caused by an insufficient blacklist during the deserialization process.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2024-11172
CVE-2024-42455

Affected Products

Veeam Backup & Replication