Executive brief
Veeam Backup and Replication contains a deserialization of untrusted data vulnerability. An unauthenticated remote attacker can exploit this by sending a malicious payload to achieve remote code execution (RCE).
Affected products
- Veeam Veeam Backup & Replication From 12.0.0.1420 up to (excluding) 12.2.0.334
Timeline
- 2024-09-07: disclosed: NVD Published Date
- 2024-10-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-10-17: advisory: Veeam KB4649 published/updated