Executive brief
The Veeam Distribution Service in Veeam Backup & Replication contains a path traversal vulnerability (CWE-22) that allows remote authenticated users to access internal API functions. This flaw can be leveraged to upload and execute arbitrary code on the affected system.
Affected products
- Veeam Backup & Replication 9.5U3, 9.5U4, 10.x, 11.x
Timeline
- 2022-12-13: disclosed
- 2022-12-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-12-13: exploited: Reported as exploited in the wild.