ZeroHour
Infosecurity Magazinepublished ()ingested Beth Maundrill

NHS England Warns of Critical Veeam Vulnerability Under Active Exploit

criticalVulnerability exploited in the wildimportance 60CVE-2024-40711

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-40711
Unauthenticated Deserialization RCE in Veeam Backup & Replication

Veeam Backup & Replication contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to send a maliciously crafted serialized payload to the product's network-facing service and achieve remote code execution, with no privileges or user interaction required (CVSS 3.1: 9.8). Successful exploitation yields full code execution on the backup server with high impact on confidentiality, integrity and availability, and is especially valuable to attackers because backup infrastructure typically stores credentials and ransomware operators seek to destroy or encrypt backups before attacking production systems. Any organization running Veeam Backup & Replication is in scope; the provided data does not specify exact affected version ranges, so consult Veeam's advisory for the affected/fixed builds. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-10-17 with known ransomware use, a public proof-of-concept has been published by watchTowr, EPSS estimates a 90.4% probability of exploitation within 30 days (100th percentile), and the exploit has been reused in Frag ransomware attacks.

Do: Apply Veeam's security updates immediately (the vendor released fixes for 18 flaws, including 5 critical ones); per the KEV required action, apply mitigations per Veeam's instructions or discontinue use if mitigations are unavailable. Until patched, restrict network access to the backup server from untrusted networks and remove unnecessary internet exposure. Given confirmed ransomware exploitation, also hunt for signs of compromise on backup servers and review backup job integrity and stored credentials.

9.890% KEV ransomware PoC
  • Veeam Backup & Replication
mass≈ hundreds of thousands of on-prem backup server deployments plausibly affected (tens of thousands internet-exposed)
Full article317 words · extracted from infosecurity-magazine.com · click to collapse

NHS England has posted an alert relating to a critical Veeam Backup & Replication vulnerability which is now under active exploitation by ransomware groups.

Successful exploitation of the vulnerability (CVE-2024-40711) could lead to remote code execution (RCE), the alert noted. RCE could allow attackers to run code on a remote device without the need for physical access.

Threat severity has been rated high, with a CVSS score of 9.8.

These groups are reportedly exploiting CVE-2024-40711 as a second stage exploit to create new local administrator accounts to facilitate further objectives on compromised networks.

Reports warn of exploitation attempts since shortly after official disclosure by Veeam.

Sophos X-Ops MDR and Incident Response has tracked a series of attacks in the past month that have leveraged compromised credentials and CVE-2024-40711 to create an account and deploy ransomware. The firm did not note the target of this attack.

In once case, attackers dropped Fog ransomware and another attack saw the attempted deployment of Akira ransomware, according to Sophos.

Veeam first issued a security bulletin relating to this and four high severity vulnerabilities on September 4, 2024.

The NHS notice highlighted that enterprise backup and disaster recovery applications are valuable targets for cyber threat groups.

Vulnerabilities in backup and disaster recovery applications are often exploited in the wild by ransomware groups shortly after official disclosure.

“NHS England National [Cybersecurity Operations Centre] assess exploitation of CVE-2024-40711 as highly likely to continue,” the advisory later said.

The vulnerability affects Veeam Backup & Replication 12.1.2.172. Veeam noted that unsupported product versions are not tested but are likely affected and should be considered vulnerable.

Affected organizations have been advised to review the Veeam Security Bulletin from and update Veeam Backup & Replication to version 12.2 (or above) as a matter of urgency.

Veeam Backup & Replication is a data protection solution that offers backup and recovery for virtual, physical, network attached storage, and cloud-native environments.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/nhs-england-warns-cve-active/