Veeam fixes critical RCEs in backup solution (CVE-2022-26500, CVE-2022-26501)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-26501 +1 in the same advisory: …26500 | Unauthenticated RCE in Veeam Backup & Replication 10.x and 11.x CVE-2022-26501 is a critical (CVSS 9.8) missing-authentication/incorrect-access-control flaw in Veeam Backup & Replication 10.x and 11.x that allows unauthenticated remote code execution; it is one of two related flaws (CVE-2022-26500 and CVE-2022-26501) fixed together by Veeam. An attacker who can reach the affected backup service over the network can trigger the flaw without any credentials or user interaction and gain code execution with full confidentiality, integrity, and availability impact on the backup server. This hands attackers control of the backup infrastructure itself, which is valuable for harvesting stored credentials, tampering with or destroying backups, and moving laterally ahead of ransomware detonation. Any organization running Veeam Backup & Replication 10.x or 11.x is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-12-13 with known ransomware use, and public reporting associates these flaws with Cuba ransomware gang activity. Do: Apply Veeam's updates per vendor instructions to all 10.x and 11.x deployments and verify the patched build is installed on every backup server. Restrict network access to Veeam backup infrastructure (including any internet-exposed or cloud-facing Veeam services) to trusted management networks, and hunt for exploitation indicators given the known ransomware use. Because exploitation is in the wild, treat patching of Veeam backup servers as urgent and high priority. | 9.8 group max | 4% | KEV ransomware |
| mass≈10^5–10^6 backup server deployments (Veeam reports roughly 500k+ customers and 10.x/11.x were the then-current versions) | |
| CVE-2022-26504 | Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allo Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe NVD description · AI analysis pending | 8.8 | 3% |
| — |
Full article304 words · extracted from helpnetsecurity.com · click to collapse
Veeam Software has patched two critical vulnerabilities (CVE-2022-26500, CVE-2022-26501) affecting its popular Veeam Backup & Replication solution, which could be exploited by unauthenticated attackers to remotely execute malicious code.

Veeam Backup & Replication is an enteprise data protection solution that allows admins to create image-level backups of virtual, physical, cloud machines and restore from them.
According to the company’s latest shared information, more than 450,000 users have downloaded Veeam Backup & Replication v11 since its launch in Q1 2021.
About the vulnerabilities (CVE-2022-26500, CVE-2022-26501)
Both vulnerabilities may allow attackers to achieve RCE and gain control over a vulnerable system.
Specifics of the vulnerabilities have not been shared, either by the company or by Nikita Petrov, the Positive Technologies researcher who discovered and reported them.
Veeam simply noted that “The Veeam Distribution Service (TCP 9380 by default) allows unauthenticated users to access internal API functions. A remote attacker may send input to the internal API which may lead to uploading and executing of malicious code.”
Veeam Backup & Replication v9.5, 10 and 11 are affected, and patches have been provided for the latter two. The company is urging users of the former to upgrade to a supported version.
If the patches cannot be implemented quickly, admins can temporarily stop and disable the Veeam Distribution Service.
In addition to fixing these flaws, the same patches also close CVE-2022-26504, another RCE hole that affects a component used for Microsoft System Center Virtual Machine Manager integration.
“The vulnerable process Veeam.Backup.PSManager.exe (TCP 8732 by default) allows authentication using non-administrative domain credentials. A remote attacker may use the vulnerable component to execute arbitrary code,” the company shared, but added that the default Veeam Backup & Replication installation is not vulnerable to this issue.
Luckily for administrators, exploits for any of these vulnerabilities are yet to be made public.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/03/15/cve-2022-26500-cve-2022-26501/