Multiple vulnerabilities have been discovered in Veeam Backup & Replication that could allow for remote code execution. Veeam Backup & Replication is a backup solutions for virtual environments. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution within the context of the application. Depending on the privileges associated with this application, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
SYSTEMS AFFECTED:
RISK:
Government:
Businesses:
Home users: Low
TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in Veeam Backup & Replication that could allow for remote code execution. Details of the vulnerabilities are as follows:
Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution within the context of the application. Depending on the privileges associated with this application, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. If this application has been configured to have fewer user rights on the system, exploitation of this vulnerability could have less impact than if it was configured with administrative rights.
RECOMMENDATIONS:
We recommend the following actions be taken:
Apply the Principle of Least Privilege to all systems and services.
REFERENCES:
CVE:
https://learn.cisecurity.org/e/799323/vename-cgi-name-CVE-2022-26500/rsfny/273051126?h=5YHbdz1H7UZ1tdNKZuImrQgB9m0Ndmbi5VDlsNU_YmE
https://learn.cisecurity.org/e/799323/vename-cgi-name-CVE-2022-26501/rsfp1/273051126?h=5YHbdz1H7UZ1tdNKZuImrQgB9m0Ndmbi5VDlsNU_YmE
https://learn.cisecurity.org/e/799323/vename-cgi-name-CVE-2022-26504/rsfp3/273051126?h=5YHbdz1H7UZ1tdNKZuImrQgB9m0Ndmbi5VDlsNU_YmE
Veeam:
https://www.veeam.com/kb4288
https://www.veeam.com/kb4290