Veeam has released updates security (September 2024 security bulletin) to fix 18 vulnerabilities in Veeam Backup & Replication, Service Provider Console , and Veeam One.

The most severe vulnerability is tracked as CVE-2024-40711. This is a critical vulnerability (CVSS v3.1 score: 9.8) that allows remote code execution (RCE) and was discovered in Veeam Backup & Replication (VBR).
See also: EstateRansomware exploits vulnerability in Veeam software
VBR is used to manage and secure enterprise backup infrastructure. The software is a favorite target of ransomware gangs, who want to steal backups and delete/encrypt backup sets so that victims have no recovery options.
In the past, the ransomware Cuba group FIN7, which has collaborated with the ransomware , have exploited vulnerabilities in Veeam Backup & Replication.
The vulnerability affects Veeam Backup & Replication 12.1.2.172 and all previous versions of the 12 branch. The vulnerabilities, which allow remote code execution, are very serious. For this reason, users are urged to immediately upgrade systems to VBR version 12.2.0.334.
See also: PoC exploit for critical vulnerability in Veeam Recovery Orchestrator
Other vulnerabilities fixed with Veeam updates affecting Backup & Replication (12.1.2.172 and earlier versions) are:
CVE-2024-40710: Allows remote code execution (RCE) and the extraction of sensitive data (stored credentials and passwords)
CVE-2024-40713: Low-privileged users can change multi-factor authentication (MFA) settings and bypass MFA.
CVE-2024-40714 : Weak TLS certificate validation allows credential theft during restore operations on the same network.
CVE-2024-39718: Low-privileged users can remove files remotely with privileges equivalent to the service account.
CVE-2024-40712: Vulnerability that allows a local user with low privileges to perform local privilege escalation (LPE).

Vulnerabilities in other Veeam products have also been fixed
Veeam has fixed four critical vulnerabilities affecting Service Provider Console (8.1.0.21377 and earlier versions) and ONE products (12.1.0.3208 and earlier versions).
See also: Veeam warns of critical vulnerability in VBEM
The above vulnerabilities highlight the importance of timely application of security updates to mitigate risks in the ever-changing cybersecurity. It is vital for organizations to prioritize software updates. But there are other measures that organizations can take to protect themselves from similar vulnerabilities. These include regularly monitoring and reviewing system logs for any suspicious activity, implementing strict access control policies , and training employees to use security best practices. It is also important for companies to have a robust incident response plan in place in the event of a security breach or incident.
Source: www.bleepingcomputer.com
