ZeroHour

CVE-2024-42455

CVSS 3.1
8.1 high
EPSS
15%p97
Published
()
Modified
Description

A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service account privileges. The vulnerability is caused by an insufficient blacklist during the deserialization process.

Vendors
veeam
Products
veeam backup \& replication
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.