Veeam: Critical Vulnerabilities Fixed in Backup and Management Solutions

veeam

Veeam recently released a series of critical security updates for several of its solutions, including Veeam Backup & Replication, Veeam Service Provider Console and Veeam ONE. A total of 18 vulnerabilities have been fixed, aiming to strengthen the security of enterprise backup infrastructures.

Critical Vulnerability in Veeam Backup & Replication

The most high-profile patch addresses a very critical vulnerability in Veeam Backup & Replication (VBR), a widely used tool for managing and securing backups within organizations. This vulnerability, CVE-2024-40711, can lead to “remote code execution” (RCE), which allows attackers to remotely execute malicious code without requiring authentication. This makes the solution especially susceptible to attacks, such as ransomware, where attackers can perform lateral movements within the network.

When attackers exploit this vulnerability, they can attack and encrypt backups, leading to ‘double’ extortion moments. Businesses risk having their backups deleted or made inaccessible, putting them in a vulnerable position and potentially forcing them to pay ransom. In the past, notorious ransomware groups such as Conti, REvil, Maze, Egregor and BlackBasta have already attempted to exploit vulnerabilities in Veeam VBR.

The patched vulnerability affects Veeam VBR version 12.1.2.172 and all earlier versions starting with 12.0. Veeam strongly recommends that users update to version 12.2.0.334 immediately to minimize security risks.

Additional Patches for Veeam Backup & Replication

In addition to the critical vulnerability mentioned above, Veeam has also addressed five other security issues in Veeam VBR. These vulnerabilities, designated CVE-2024-40710, CVE-2024-40713, CVE-2024-40714, CVE-2024-39718 and CVE-2024-40712, are classified as “high” risk and have been patched in the update for version 12.1.2.172 and older.

Veeam Service Provider Console

Veeam Service Provider Console, a widely used backup management solution for service providers, has also received important security updates. Vulnerability CVE-2024-38650 has been fixed, which allowed attackers with low user privileges to access the NTLM hash of the service account on the VSPC server. In addition, vulnerability CVE-2024-39714 has been addressed, which now makes it impossible for a user with low privileges to upload arbitrary files to the server and thus perform RCE attacks.

Patches for Veeam ONE

Veeam ONE, a monitoring and analysis solution for backup environments, also received important security updates. Vulnerability CVE-2024-42024, which allowed attackers to execute RCE on the host machine via a ONE Agent service account, has been fixed. Additionally, vulnerability CVE-2024-42019, which allowed hackers to access the NTLM hash of the Reporter Service account, after previous data collection via Veeam VBR, has been patched.

Why These Updates Are Important

This series of patches highlights the importance of regular updates for organizations using Veeam solutions to protect their backups and critical data. Fixed vulnerabilities pose a real risk to businesses and can lead to serious breaches, especially when ransomware groups exploit such weaknesses.

To keep your infrastructure secure, IT administrators are advised to update all Veeam solutions to the latest versions as soon as possible. Performing these updates is critical to preventing attacks and ensuring the integrity of corporate data fortunately for all of us it is “super logical” and the customers still using Veeam are all patched.

If you need help, we are happy to help!

Recent blogs

apple header
Blog
Apple 50 Years: 50 Years of Daring to Think Differently
This year, Apple celebrates its 50th anniversary. A milestone that cannot simply be overlooked. Because whether you are a fan or not: Apple has permanently changed the way we work, communicate, and create. At Analyst ICT, we are proud to be part of this ecosystem. As an Apple Technical Partner, we work daily with technology that is not only powerful but, above all, logical and pleasant to use. A different perspective on technology Apple has always distinguished itself by one simple conviction: technology should help people, not hinder them. No unnecessary complexity, but simplicity and ease of use. That aligns seamlessly...
browser password
Blog
Why saving passwords in your browser is not a good idea
The blog post below was created in response to a question during our engineering meeting. Every two weeks, we get together with all of our technical staff to discuss the latest developments in technology or with clients. Good client questions also arise during these meetings, such as this one. Time to do some research. Thank you, Wiebe! You've probably experienced this: you log in to a website, and your browser asks if it should remember your password. Convenient, fast, and you don't have to remember anything. However, there's a risk involved. In practice, we see that many security incidents start with something small. Like saving passwords…
Apple Business
Blog
Apple is taking a big step with Apple Business
Apple announced something special this week. Not a new device, but something that might be even more interesting for many organizations: Apple Business. A completely new platform with which Apple brings all its business services together in one environment. And frankly: this is a development that we at Analyst ICT are following with great interest. The problem: fragmented tools and unnecessary complexity Many organizations working with Apple will recognize the problem: Multiple portals (Apple Business Manager, Business Essentials, Connect) Different tools for management, branding, and support Additional costs for basic functionalities such as device management This leads to a lack of clarity and costs time. And…

A newsletter

Superlogic right?