Skip to content
COOEY

EXPOSURES › CVE-2024-40711

CVE-2024-40711

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-10-17 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-40711 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Veeam Backup and Replication suffered a deserialization vulnerability allowing unauthenticated remote code execution, linked to ransomware attacks.

Veeam Backup and Replication contained a deserialization flaw enabling unauthenticated remote code execution, directly tied to ransomware incidents. DIB organizations must ensure all backup infrastructure is patched and monitored, as attackers exploit such vulnerabilities to gain persistent access and encrypt critical data. This failure highlights the risk of relying on unpatched third-party software for essential recovery systems.

Shame score — A critical deserialization vulnerability allowing unauthenticated remote code execution was actively exploited in the wild and linked to ransomware, indicating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.