Junglewise Threat Intelligence

CVE-2024-40711: Veeam Backup and Replication Deserialization Vulnerability

CVE-2024-40711 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-10-17

Executive brief

Veeam Backup and Replication contains a deserialization of untrusted data vulnerability. An unauthenticated remote attacker can exploit this by sending a malicious payload to achieve remote code execution (RCE).

Affected products

  • Veeam Veeam Backup & Replication From 12.0.0.1420 up to (excluding) 12.2.0.334

Timeline

  • 2024-09-07: disclosed: NVD Published Date
  • 2024-10-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-10-17: advisory: Veeam KB4649 published/updated

Related threats