Junglewise Threat Intelligence

CVE-2022-26500: Veeam Backup & Replication Remote Code Execution Vulnerability

CVE-2022-26500 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-12-13

Technologies: Nakivo Backup, Nakivo Replication, Veeam Backup & Replication. Vendors: Nakivo, Veeam.

Executive brief

The Veeam Distribution Service in Veeam Backup & Replication contains a path traversal vulnerability (CWE-22) that allows remote authenticated users to access internal API functions. This flaw can be leveraged to upload and execute arbitrary code on the affected system.

Affected products

  • Veeam Backup & Replication 9.5U3, 9.5U4, 10.x, 11.x

Timeline

  • 2022-12-13: disclosed
  • 2022-12-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-12-13: exploited: Reported as exploited in the wild.

Related threats