CyberzSOC

Publication detail
← Back to advisories & guidance

2024-092: Critical Vulnerability in Veeam ↗ source

September 6, 2024 CERT-EU Advisory

Summary

This flaw allows unauthenticated attackers to execute arbitrary code on vulnerable systems (CVSS score: 9.8). VBR is a target for ransomware attacks, as it plays a key role in enterprise data protection. Users are advised to update to version 12.2.0.334 as soon as possible. The vulnerability tracked as CVE-2024-40711 enables remote, unauthenticated code execution on vulnerable VBR systems, potentially leading to lateral movement and full infrastructure CERT-EU recommends updating to VBR version 12.2.0.334 as soon as possible.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-40711 9.8 Critical Veeam Backup & Replication Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.