Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-40717

Опубликовано: 04 дек. 2024
Источник: nvd
CVSS3: 8.8
CVSS3: 8.8
EPSS Низкий

Описание

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*
Версия от 12.0.0.1402 (включая) до 12.3.0.310 (исключая)

EPSS

Процентиль: 90%
0.05884
Низкий

8.8 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.8
github
около 1 года назад

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server.

EPSS

Процентиль: 90%
0.05884
Низкий

8.8 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-306