Description

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server.

INFO

Published Date :

2024-12-04T01:06:04.636Z

Last Modified :

2025-03-13T17:40:27.483Z

Source :

hackerone
AFFECTED PRODUCTS

The following products are affected by CVE-2024-40717 vulnerability.

Vendors Products
Veeam
  • Backup And Replication
  • Veeam Backup \& Replication
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-40717.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact