ZeroHour
Security Affairspublished ()ingested @securityaffairs

Critical flaws affect Veeam Data Backup software

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-26501
+1 in the same advisory: …26500
Unauthenticated RCE in Veeam Backup & Replication 10.x and 11.x

CVE-2022-26501 is a critical (CVSS 9.8) missing-authentication/incorrect-access-control flaw in Veeam Backup & Replication 10.x and 11.x that allows unauthenticated remote code execution; it is one of two related flaws (CVE-2022-26500 and CVE-2022-26501) fixed together by Veeam. An attacker who can reach the affected backup service over the network can trigger the flaw without any credentials or user interaction and gain code execution with full confidentiality, integrity, and availability impact on the backup server. This hands attackers control of the backup infrastructure itself, which is valuable for harvesting stored credentials, tampering with or destroying backups, and moving laterally ahead of ransomware detonation. Any organization running Veeam Backup & Replication 10.x or 11.x is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-12-13 with known ransomware use, and public reporting associates these flaws with Cuba ransomware gang activity.

Do: Apply Veeam's updates per vendor instructions to all 10.x and 11.x deployments and verify the patched build is installed on every backup server. Restrict network access to Veeam backup infrastructure (including any internet-exposed or cloud-facing Veeam services) to trusted management networks, and hunt for exploitation indicators given the known ransomware use. Because exploitation is in the wild, treat patching of Veeam backup servers as urgent and high priority.

9.8
group max
4% KEV ransomware
  • Veeam Backup & Replication 10.x and 11.x
mass≈10^5–10^6 backup server deployments (Veeam reports roughly 500k+ customers and 10.x/11.x were the then-current versions)
CVE-2022-26503
Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privi

Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.

NVD description · AI analysis pending
7.8<1%
  • veeam veeam
CVE-2022-26504
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allo

Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe

NVD description · AI analysis pending
8.83%
  • veeam veeam backup \& replication
Full article293 words · extracted from securityaffairs.com · click to collapse

Veeam addressed two critical vulnerabilities impacting the Backup & Replication product for virtual environments.

Veeam has released security patches to fix two critical vulnerabilities, tracked as CVE-2022-26500 and CVE-2022-26501 (CVSS score of 9.8), impacting the Backup & Replication solution for virtual environments.

The solution implements data backup and restore capabilities for virtual machines running on Hyper-V, vSphere, VMware, Windows & Linux servers, laptops, NAS and more

A remote, unauthenticated attacker could exploit both issues to execute arbitrary code potentially leading to a complete takeover of the target system.

“Multiple vulnerabilities (CVE-2022-26500, CVE-2022-26501) in Veeam Backup & Replication allow executing malicious code remotely without authentication. This may lead to gaining control over the target system.” reads the advisory published by the company. “The Veeam Distribution Service (TCP 9380 by default) allows unauthenticated users to access internal API functions. A remote attacker may send input to the internal API which may lead to uploading and executing of malicious code.”

The flaws reside in the Veeam Distribution Service that allows unauthenticated users to access internal API functions. The two vulnerabilities were reported by Nikita Petrov from Positive Technologies.

CVE-2022-26504 impacts the component used for Microsoft System Center Virtual Machine Manager (SCVMM) integration. An attacker without administrative domain credentials could achieve remote code execution by exploiting this issue.

CVE-2022-26503 impacts Veeam Agent for Microsoft Windows, it could be exploited by an attacker to elevate privileges and run arbitrary code as LOCAL SYSTEM.

Both issues impact Veeam Backup & Replication versions 9.5, 10, and 11, unfortunately, security patches for versions 9.5 are not available.

The vendor recommends disabling the Veeam Distribution Service as temporary mitigation.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, RCE)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/129094/hacking/veeam-rce.html