nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-45204 CVE-2024-45204
MEDIUM
Record summary
CVE-2024-45204 has a selected CVSS score of 4.3 (medium).
Description
A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial target and potentially leading to broader security vulnerabilities.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 4, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Backup & ReplicationBrowse Veeam / Backup & ReplicationDefault status: unaffected | CVE List | 12.2 to ≤ 12.2 | affected |
References
2veeam.com
https://www.veeam.com/kb4693