A vulnerability has been identified and reported within the Veeam platform, identification for this is CVE-2024-40711. It has been classified as critical. Reported by Florian Hauser with Code White Gmbh the vulnerability is currently under active exploitation.
The exploit is being used by ransomware groups to create new local administrator accounts to carry out further attacks off the back of this. This has been classed as RCE exploit which stands for ‘Remote Code Execution’ and is one of the most serious vulnerabilities.
Corporate backup and disaster recovery solutions are one of the biggest targets for attackers usually for some kind of profit gain off the back of a cyber attack.
Solution
https://www.veeam.com/kb4649
Products that have been identified are below…
- Veeam Backup & Replication
- Veeam One
- Veeam Service Provider Console
- Veeam Agent for Linux
- Veeam Backup for Nutanix AHV
- Veeam Backup for Oracle Linux Virtualization Manager and Red
- Hat Virtualization
Our Customers
If you are one of our customers there is no need to worry, none of our customers are affected by this exploit due to us not using this application for backup and disaster recovery.
If you are not one of our customers but looking for advice on backup and disaster recovery we can help, either book a call with our sales team to discuss further or view our page on the services that we can provide.