ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449)

highVulnerability exploited in the wildimportance 60CVE-2024-42448CVE-2024-42449

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-42448
Authorized-agent RCE in Veeam Service Provider Console (VSPC)

CVE-2024-42448 is a code-injection flaw (CWE-94) in Veeam Service Provider Console (VSPC) that enables remote code execution on the VSPC server machine. It is triggered from a machine running the VSPC management agent when that agent is authorized on the server: an attacker who controls an authorized agent, or its credentials, can send crafted input that executes code on the central VSPC server, consistent with the critical CVSS 9.9 score (network vector, low privileges, changed scope, high confidentiality/integrity/availability impact). Because the VSPC server is the multi-tenant management hub for service providers, code execution there can hand an attacker control of the management platform and a foothold spanning all customer environments it manages. Those affected are Veeam service-provider and MSP partners running VSPC; Veeam patched this flaw alongside CVE-2024-42449 and urged immediate updates. There is no known public PoC or confirmed in-the-wild exploitation yet, but EPSS assigns a roughly 20% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk.

Do: Upgrade VSPC to the fixed build specified in Veeam's security advisory as soon as possible, in line with the vendor's urgent patching guidance. Until patched, inventory and monitor machines running authorized VSPC management agents and check for signs of compromise on them, since a single authorized agent is enough to reach the VSPC server. Consider restricting network access to the VSPC server and reviewing which agents hold authorization credentials.

9.920%
  • Veeam Service Provider Console (VSPC)
moderatea few thousand VSPC server deployments (MSP/hoster-installed), each overseeing many tenant machines via agents
CVE-2024-42449
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the V

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine.

NVD description · AI analysis pending
7.16%
Full article294 words · extracted from helpnetsecurity.com · click to collapse

Veeam has fixed two vulnerabilities in Veeam Service Provider Console (VSPC), one of which (CVE-2024-42448) may allow remote attackers to achieve code exection on the VSPC server machine.

VSPC vulnerabilities CVE-2024-42448

The vulnerabilities

Veeam Service Provider Console is a cloud-enabled platform that allows enterprises to manage and monitor backup operations across their offices. It’s also used by service providers to deliver Backup-as-a-Service (BaaS) and Disaster Recovery-as-a-Service (DRaaS) services to customers.

The solution uses management agents to interact with machines in managed infrastructures that run Veeam backup, disaster recovery and IT monitoring/reporting products.

CVE-2024-42448 allows remote code execution from the VSPC management agent machine on the VSPC server machine – if the management agent is authorized on the server.

CVE-2024-42449 allows attackers to leak an NTLM hash of the VSPC server service account and delete files on the VSPC server machine – if they have a presence on the VSPC management agent machine and if the management agent is authorized on the server.

Additional information about the vulnerabilities is still under wraps.

Upgrade quickly!

Both CVE-2024-42448 and CVE-2024-42449 have been discovered during internal testing and Veeam does not mention in-the-wild exploitation.

They affect Veeam Service Provider Console 8.1.0.21377 and all earlier versions 8 and 7 builds, and have been fixed in Veeam Service Provider Console v8.1.0.21999.

“We encourage service providers using supported versions of Veeam Service Provider Console (versions 7 & 8) to update to the latest cumulative patch. Service Providers using unsupported versions are strongly encouraged to upgrade to the latest version of Veeam Service Provider Console,” the company advised.

Upgrading is the only way to plug these holes, as there is no mitigation available.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/12/03/vspc-vulnerabilities-cve-2024-42448-cve-2024-42449/