Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rcf7-pr2j-6q2c

Опубликовано: 04 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server.

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server.

EPSS

Процентиль: 90%
0.05884
Низкий

8.8 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server.

EPSS

Процентиль: 90%
0.05884
Низкий

8.8 High

CVSS3

Дефекты

CWE-306