ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Multiple RCE Vulnerabilities Discovered in Veeam Backup & Replication App

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-26501
+1 in the same advisory: …26500
Unauthenticated RCE in Veeam Backup & Replication 10.x and 11.x

CVE-2022-26501 is a critical (CVSS 9.8) missing-authentication/incorrect-access-control flaw in Veeam Backup & Replication 10.x and 11.x that allows unauthenticated remote code execution; it is one of two related flaws (CVE-2022-26500 and CVE-2022-26501) fixed together by Veeam. An attacker who can reach the affected backup service over the network can trigger the flaw without any credentials or user interaction and gain code execution with full confidentiality, integrity, and availability impact on the backup server. This hands attackers control of the backup infrastructure itself, which is valuable for harvesting stored credentials, tampering with or destroying backups, and moving laterally ahead of ransomware detonation. Any organization running Veeam Backup & Replication 10.x or 11.x is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-12-13 with known ransomware use, and public reporting associates these flaws with Cuba ransomware gang activity.

Do: Apply Veeam's updates per vendor instructions to all 10.x and 11.x deployments and verify the patched build is installed on every backup server. Restrict network access to Veeam backup infrastructure (including any internet-exposed or cloud-facing Veeam services) to trusted management networks, and hunt for exploitation indicators given the known ransomware use. Because exploitation is in the wild, treat patching of Veeam backup servers as urgent and high priority.

9.8
group max
4% KEV ransomware
  • Veeam Backup & Replication 10.x and 11.x
mass≈10^5–10^6 backup server deployments (Veeam reports roughly 500k+ customers and 10.x/11.x were the then-current versions)
CVE-2022-26504
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allo

Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe

NVD description · AI analysis pending
8.83%
  • veeam veeam backup \& replication
Full article322 words · extracted from infosecurity-magazine.com · click to collapse

Several critical and high-severity vulnerabilities have been discovered affecting the Veeam Backup & Replication application that could be exploited by advertising fully weaponized tools for remote code execution (RCE).

The findings come from security researchers at CloudSEK, who published an advisory about them earlier today.

“Several threat actors were seen advertising the fully weaponized tool for remote code execution to exploit the following vulnerabilities affecting Veeam Backup & Replication: CVE-2022-26500 and CVE-2022-26501 with a CVSS V3 score of 9.8 and CVE-2022-26504 with a CVSS V3 score of 8.8,” reads the technical write-up.

According to CloudSEK, the successful exploitation of these common vulnerabilities and exposures (CVEs) can lead to copying files within the boundaries of the locale or from a remote Server Message Block (SMB) network, RCE without authorization or RCE/LPE without authorization.

From a technical standpoint, Veeam Backup & Replication is a proprietary backup app for virtual environments built on VMware vSphere, Nutanix AHV and Microsoft Hyper-V hypervisors.

The application not only backs up and recovers virtual machines (VMs) but can also be used to protect and restore individual files and applications for environments such as Exchange and SharePoint.

As for attribution, CloudSEK has said malware named ‘Veeamp’ was found in the wild and used by the Monti and Yanluowang ransomware groups to dump credentials from an SQL database for Veeam backup management software.

The company has also found a GitHub repository named “veeam-creds” that contained scripts for recovering passwords from the Veeam Backup & Replication credential manager alongside three malicious files.

CloudSEK has disclosed the above vulnerabilities to Veeam, which has already released patches in the 11.0.1.1261 version of its software.

The text of the CloudSEK advisory is available on the company website and contains a complete list of Indicators of Compromise (IoCs).

Its publication comes a couple of months after virtualization technology software firm VMware released patches to fix a severe vulnerability in its VMware Tools suite of utilities.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/rce-vulnerabilities-in-veeam/