CVE-2024-42455

A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service account privileges. The vulnerability is caused by an insufficient blacklist during the deserialization process.
References
Link Resource
https://www.veeam.com/kb4693 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*

History

24 Apr 2025, 17:10

Type Values Removed Values Added
CPE cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*
References () https://www.veeam.com/kb4693 - () https://www.veeam.com/kb4693 - Vendor Advisory
First Time Veeam veeam Backup \& Replication
Veeam
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 8.1

05 Dec 2024, 11:15

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en Veeam Backup & Replication permite que un usuario con pocos privilegios se conecte a servicios remotos y aproveche la deserialización insegura mediante el envío de una colección de archivos temporales serializados. Esta vulnerabilidad permite al atacante eliminar cualquier archivo del sistema con privilegios de cuenta de servicio. La vulnerabilidad se debe a una lista negra insuficiente durante el proceso de deserialización.
CWE CWE-306

04 Dec 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-04 02:15

Updated : 2025-04-24 17:10


NVD link : CVE-2024-42455

Mitre link : CVE-2024-42455

CVE.ORG link : CVE-2024-42455


JSON object : View

Products Affected

veeam

  • veeam_backup_\&_replication
CWE
CWE-306

Missing Authentication for Critical Function