Veeam addressed critical Service Provider Console (VSPC) bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-40711 | Unauthenticated Deserialization RCE in Veeam Backup & Replication Veeam Backup & Replication contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to send a maliciously crafted serialized payload to the product's network-facing service and achieve remote code execution, with no privileges or user interaction required (CVSS 3.1: 9.8). Successful exploitation yields full code execution on the backup server with high impact on confidentiality, integrity and availability, and is especially valuable to attackers because backup infrastructure typically stores credentials and ransomware operators seek to destroy or encrypt backups before attacking production systems. Any organization running Veeam Backup & Replication is in scope; the provided data does not specify exact affected version ranges, so consult Veeam's advisory for the affected/fixed builds. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-10-17 with known ransomware use, a public proof-of-concept has been published by watchTowr, EPSS estimates a 90.4% probability of exploitation within 30 days (100th percentile), and the exploit has been reused in Frag ransomware attacks. Do: Apply Veeam's security updates immediately (the vendor released fixes for 18 flaws, including 5 critical ones); per the KEV required action, apply mitigations per Veeam's instructions or discontinue use if mitigations are unavailable. Until patched, restrict network access to the backup server from untrusted networks and remove unnecessary internet exposure. Given confirmed ransomware exploitation, also hunt for signs of compromise on backup servers and review backup job integrity and stored credentials. | 9.8 | 90% | KEV ransomware PoC |
| mass≈ hundreds of thousands of on-prem backup server deployments plausibly affected (tens of thousands internet-exposed) | |
| CVE-2024-42448 | Authorized-agent RCE in Veeam Service Provider Console (VSPC) CVE-2024-42448 is a code-injection flaw (CWE-94) in Veeam Service Provider Console (VSPC) that enables remote code execution on the VSPC server machine. It is triggered from a machine running the VSPC management agent when that agent is authorized on the server: an attacker who controls an authorized agent, or its credentials, can send crafted input that executes code on the central VSPC server, consistent with the critical CVSS 9.9 score (network vector, low privileges, changed scope, high confidentiality/integrity/availability impact). Because the VSPC server is the multi-tenant management hub for service providers, code execution there can hand an attacker control of the management platform and a foothold spanning all customer environments it manages. Those affected are Veeam service-provider and MSP partners running VSPC; Veeam patched this flaw alongside CVE-2024-42449 and urged immediate updates. There is no known public PoC or confirmed in-the-wild exploitation yet, but EPSS assigns a roughly 20% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk. Do: Upgrade VSPC to the fixed build specified in Veeam's security advisory as soon as possible, in line with the vendor's urgent patching guidance. Until patched, inventory and monitor machines running authorized VSPC management agents and check for signs of compromise on them, since a single authorized agent is enough to reach the VSPC server. Consider restricting network access to the VSPC server and reviewing which agents hold authorization credentials. | 9.9 | 20% |
| moderatea few thousand VSPC server deployments (MSP/hoster-installed), each overseeing many tenant machines via agents | ||
| CVE-2024-42449 | From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the V From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine. NVD description · AI analysis pending | 7.1 | 6% | — | — |
Full article352 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 04, 2024

Veeam addressed a critical vulnerability in Service Provider Console (VSPC) that could allow remote attackers to execute arbitrary code.
Veeam released security updates for a critical vulnerability, tracked as CVE-2024-42448 (CVSS score of 9.9) impacting Service Provider Console. Successful exploitation of the flaw can potentially lead to remote code execution on vulnerable installs.
Veeam Service Provider Console (VSPC) is a management and monitoring solution designed for service providers offering backup, disaster recovery, and cloud services. It enables centralized management of Veeam-powered solutions across multiple tenants, providing tools for billing, reporting, and automated deployment.
The vulnerability affects Veeam Service Provider Console 8.1.0.21377 and all earlier versions 8 and 7 builds.
“From the VSPC management agent machine, under the condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.” reads the advisory.
The company confirmed that its experts discovered the vulnerability during internal testing.
Veeam also addressed a vulnerability, tracked as CVE-2024-42449 (CVSS score 7.1) that could be exploited to leak an NTLM hash of the VSPC server service account and delete files on the VSPC server machine.
“From the VSPC management agent machine, under the condition that the management agent is authorized on the server, it is possible to leak an NTLM hash of the VSPC server service account and delete files on the VSPC server machine.” reads the advisory.
Both vulnerabilities have been addressed in version 8.1.0.21999.
Organizations are recommended to upgrade to the latest version of the software.
In the past, threat actors exploited Veeam flaws for ransomware attacks. In November, researchers reported that a critical flaw, tracked as CVE-2024-40711, in Veeam Backup & Replication (VBR) was exploited to deploy Frag ransomware.
After the Akira and Fog ransomware attacks, experts warned of threat actors attempting to deploy Frag ransomware actively exploiting CVE-2024-40711.
In mid-October, Sophos researchers warned that ransomware operators are exploiting the vulnerability CVE-2024-40711 to create rogue accounts and deploy malware.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Service Provider Console)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/171651/security/veeam-addressed-critical-service-provider-console-vspc-flaw.html