packetstormsecurity.com
http://packetstormsecurity.com/files/157529/Veeam-ONE-Agent-.NET-Deserialization.html CVE-2020-10914
CRITICAL
Veeam ONE Agent .NET Deserialization
Record summary
CVE-2020-10914 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the PerformHandshake method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-10400.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
One AgentBrowse VEEAM / One Agent | CVE List | 9.5.4.4587 | affected |
Proofs of concept
1Catalogued exploits
MetasploitVeeam ONE Agent .NET DeserializationMetasploit exploitby Edgar Boda-Majer +2 moreNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-10914 veeam.com
https://www.veeam.com/kb3144 zerodayinitiative.com
https://www.zerodayinitiative.com/advisories/ZDI-20-545