CVE-2024-42448
moderateAuthorized-agent RCE in Veeam Service Provider Console (VSPC)
CVE-2024-42448 is a code-injection flaw (CWE-94) in Veeam Service Provider Console (VSPC) that enables remote code execution on the VSPC server machine. It is triggered from a machine running the VSPC management agent when that agent is authorized on the server: an attacker who controls an authorized agent, or its credentials, can send crafted input that executes code on the central VSPC server, consistent with the critical CVSS 9.9 score (network vector, low privileges, changed scope, high confidentiality/integrity/availability impact). Because the VSPC server is the multi-tenant management hub for service providers, code execution there can hand an attacker control of the management platform and a foothold spanning all customer environments it manages. Those affected are Veeam service-provider and MSP partners running VSPC; Veeam patched this flaw alongside CVE-2024-42449 and urged immediate updates. There is no known public PoC or confirmed in-the-wild exploitation yet, but EPSS assigns a roughly 20% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk.
What to do: Upgrade VSPC to the fixed build specified in Veeam's security advisory as soon as possible, in line with the vendor's urgent patching guidance. Until patched, inventory and monitor machines running authorized VSPC management agents and check for signs of compromise on them, since a single authorized agent is enough to reach the VSPC server. Consider restricting network access to the VSPC server and reviewing which agents hold authorization credentials.
| Veeam Service Provider Console (VSPC) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.
- Weakness
- CWE-94
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H