Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hw3m-2wrm-879c

Опубликовано: 04 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service account privileges. The vulnerability is caused by an insufficient blacklist during the deserialization process.

A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service account privileges. The vulnerability is caused by an insufficient blacklist during the deserialization process.

EPSS

Процентиль: 89%
0.04745
Низкий

7.1 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 года назад

A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service account privileges. The vulnerability is caused by an insufficient blacklist during the deserialization process.

CVSS3: 7.1
fstec
больше 1 года назад

Уязвимость средства защиты облачных, виртуальных и физических систем Veeam Backup & Replication, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю получить несанкционированный доступ на чтение, изменение или удаление данных

EPSS

Процентиль: 89%
0.04745
Низкий

7.1 High

CVSS3

Дефекты

CWE-306