nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-42455 CVE-2024-42455
HIGH
Record summary
CVE-2024-42455 has a selected CVSS score of 8.1 (high).
Description
A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service account privileges. The vulnerability is caused by an insufficient blacklist during the deserialization process.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 5, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Backup & ReplicationBrowse Veeam / Backup & ReplicationDefault status: unaffected | CVE List | 12.2 to ≤ 12.2 | affected |
backup_and_replicationBrowse veeam / backup_and_replicationDefault status: unknown | CVE List | 12.0 to ≤ 12.2.0.334 | affected |
References
2veeam.com
https://www.veeam.com/kb4693