ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Veeam Urges Immediate Update to Patch Severe Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-42448
Authorized-agent RCE in Veeam Service Provider Console (VSPC)

CVE-2024-42448 is a code-injection flaw (CWE-94) in Veeam Service Provider Console (VSPC) that enables remote code execution on the VSPC server machine. It is triggered from a machine running the VSPC management agent when that agent is authorized on the server: an attacker who controls an authorized agent, or its credentials, can send crafted input that executes code on the central VSPC server, consistent with the critical CVSS 9.9 score (network vector, low privileges, changed scope, high confidentiality/integrity/availability impact). Because the VSPC server is the multi-tenant management hub for service providers, code execution there can hand an attacker control of the management platform and a foothold spanning all customer environments it manages. Those affected are Veeam service-provider and MSP partners running VSPC; Veeam patched this flaw alongside CVE-2024-42449 and urged immediate updates. There is no known public PoC or confirmed in-the-wild exploitation yet, but EPSS assigns a roughly 20% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk.

Do: Upgrade VSPC to the fixed build specified in Veeam's security advisory as soon as possible, in line with the vendor's urgent patching guidance. Until patched, inventory and monitor machines running authorized VSPC management agents and check for signs of compromise on them, since a single authorized agent is enough to reach the VSPC server. Consider restricting network access to the VSPC server and reviewing which agents hold authorization credentials.

9.920%
  • Veeam Service Provider Console (VSPC)
moderatea few thousand VSPC server deployments (MSP/hoster-installed), each overseeing many tenant machines via agents
CVE-2024-42449
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the V

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine.

NVD description · AI analysis pending
7.16%
Full article354 words · extracted from infosecurity-magazine.com · click to collapse

Two severe vulnerabilities in Veeam Service Provider Console (VSPC) software have been patched, including one with a near-maximum CVSS score of 9.9. The issues, designated as CVE-2024-42448 and CVE-2024-42449, were identified during internal testing by Veeam.

Both flaws pose significant risks to system integrity, requiring immediate attention from affected service providers.

Details of the Vulnerabilities

Rated as critical with a CVSS v3.1 score of 9.9, CVE-2024-42448 is a remote code execution vulnerability on the VSPC server machine via an authorized management agent. 

“A critical vulnerability in the VSPC presents a significant risk to organizations using this software,” commented Eric Schwake, director of cybersecurity strategy at Salt Security. “With a CVSS score of 9.9, this vulnerability allows for remote code execution on affected instances, potentially enabling attackers to gain complete control of the system and compromise sensitive data.”

Meanwhile, CVE-2024-42449 enables leaking of an NTML hash of the VSPC server service account and deletion of files on the server machine. This vulnerability is rated as high severity, with a CVSS v3.1 score of 7.1.

These vulnerabilities impact all VSPC versions 8.1.0.21377 and earlier versions of builds 7 and 8. Unsupported product versions are likely vulnerable and should be updated.

Recommended Actions

Veeam has released a patch for these issues in build 8.1.0.21999. Users of supported versions are urged to apply this update immediately. Those running unsupported versions are strongly encouraged to upgrade to the latest VSPC release.

No mitigation methods are available, making the update the only viable solution to address these security flaws.

Read more on cybersecurity best practices: CISO Best Practices for Managing Cyber Risk

“To mitigate these risks, service providers and vendors must prioritize timely patching and vulnerability management to reduce the attack surface, while companies should implement a multi-layered security approach, combining secure backups, regular patching cycles and effective incident response plans,” said Elad Luz, head of research at Oasis Security.

“Without such measures, businesses leave themselves vulnerable to significant cybersecurity threats, underlining the need for robust vendor security management and continuous security monitoring within both their internal systems and the services they rely on.”

Image credit: T. Schneider / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/veeam-urges-update-patch/