CVE-2024-42452
04.12.2024, 02:15
A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges. The vulnerability exists because remote calls bypass permission checks, leading to full system compromise.Enginsight
Vendor | Product | Version |
---|---|---|
veeam | veeam_backup_\&_replication | 12.0.0.1402 ≤ 𝑥 < 12.3.0.310 |
𝑥
= Vulnerable software versions
References