CVE-2024-40711
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

A deserialization of untrusted data vulnerability (CVE-2024-40711) was discovered in Veeam Backup & Replication software versions 12.1.2.172 and earlier. The vulnerability allows an unauthenticated attacker to achieve remote code execution (RCE). This critical vulnerability was reported by Florian Hauser with CODE WHITE GmbH and was disclosed on September 4, 2024 (Veeam KB, Censys Report).

Technical details

The vulnerability stems from an insecure deserialization issue involving the System.Runtime.Remoting.ObjRef .NET class type, which is a known deserialization gadget. The vulnerability received a CVSS v3.1 score of 9.8 (Critical) with the vector string CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating high severity across confidentiality, integrity, and availability impacts (Veeam KB).

Impact

The vulnerability enables attackers to gain full control of affected systems, manipulate data, and potentially move laterally within networks. Given Veeam's role in enterprise backup systems, this vulnerability is particularly concerning as it could be exploited by ransomware operators to compromise backup systems and create double-extortion scenarios (Censys Report).

Mitigation and workarounds

Veeam has released security patches addressing CVE-2024-40711 in version 12.2.0.334. Users are strongly advised to upgrade their systems to this version immediately. The patch includes fixes for this vulnerability along with several other security issues (Veeam KB).

Community reactions

The vulnerability has garnered significant attention due to Veeam's widespread use in enterprise environments and its critical role in backup systems. CODE WHITE GmbH, who discovered the vulnerability, noted on social media that they withheld technical details to prevent immediate abuse by ransomware gangs (Watchtowr Labs).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management