ZeroHour

CVE-2024-42448

moderate

Authorized-agent RCE in Veeam Service Provider Console (VSPC)

CVSS 3.0
9.9 critical
EPSS
20%p97
Published
()
Modified
AI analysis

CVE-2024-42448 is a code-injection flaw (CWE-94) in Veeam Service Provider Console (VSPC) that enables remote code execution on the VSPC server machine. It is triggered from a machine running the VSPC management agent when that agent is authorized on the server: an attacker who controls an authorized agent, or its credentials, can send crafted input that executes code on the central VSPC server, consistent with the critical CVSS 9.9 score (network vector, low privileges, changed scope, high confidentiality/integrity/availability impact). Because the VSPC server is the multi-tenant management hub for service providers, code execution there can hand an attacker control of the management platform and a foothold spanning all customer environments it manages. Those affected are Veeam service-provider and MSP partners running VSPC; Veeam patched this flaw alongside CVE-2024-42449 and urged immediate updates. There is no known public PoC or confirmed in-the-wild exploitation yet, but EPSS assigns a roughly 20% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk.

What to do: Upgrade VSPC to the fixed build specified in Veeam's security advisory as soon as possible, in line with the vendor's urgent patching guidance. Until patched, inventory and monitor machines running authorized VSPC management agents and check for signs of compromise on them, since a single authorized agent is enough to reach the VSPC server. Consider restricting network access to the VSPC server and reviewing which agents hold authorization credentials.

Affected
Veeam Service Provider Console (VSPC)
Estimated exposure
moderatea few thousand VSPC server deployments (MSP/hoster-installed), each overseeing many tenant machines via agents — VSPC is a service-provider-focused multi-tenant management console rather than a broadly deployed end-user product, so the vulnerable component (the VSPC server) is plausibly installed on the order of thousands at MSPs and hosters; no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news