Veeam Backup and Replication deserialization (CVE-2024-40711) — take the means of restoring and there is nowhere to restore to
A deserialization vulnerability in backup software, described as allowing an unauthenticated user to perform remote code execution. Backup is the means of returning from harm, and taking it removes the premise of recovery.
Key facts
- CVE IDCVE-2024-40711
- Affected (vendor / product)Veeam Backup & Replication
- CWECWE-502
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2024-11-07 (U.S. federal civilian agencies, BOD 22-01)
Key points
- The affected product is Veeam Backup & Replication, classified as deserialization of untrusted data.
- An unauthenticated user is described as able to perform remote code execution, and use in ransomware campaigns is known.
- Backup is the means of returning from harm, so taking it removes the premise of recovery.
- A backup system must connect across the whole of an organization systems, and that breadth is also the breadth of any effect.
- Added October 17, 2024 with a due date of November 7, 21 days later.
1Cutting off the way back first
When data is encrypted or lost, an organization turns to its backups. That is exactly why the backup system itself becomes a target: with the means of recovery unavailable, the remaining options narrow.
Backup is an unobtrusive system in normal times. Its running is taken for granted, and it tends to slip down the list for updates. That this entry is marked as known in ransomware campaigns is not unrelated to that position.
2The class of flaw
- 1The mechanismRestoring data converted for storage or transmission back to its original structure
- 2During restorationThe structure is rebuilt following the content received
- 3Where trouble arisesWhere what arrives from an untrusted party is restored as it stands
- 4The condition hereAn unauthenticated user may perform remote code execution
This site has a separate article devoted to this class. What stands out here is that no authentication is required: someone holding no credentials, merely positioned to send requests to this system, is enough.
3How backup is placed
A backup system cannot do its job without connecting across the whole of an organization systems. That breadth of connection is also the breadth of what an effect can reach. This site covers the same shape for tools placed there to support and operate, where breadth required by a role becomes a weakness.
4Checking in normal times
Having backups and being able to restore from them are different things. Equally, a system running and that system itself being protected are different things. Whether a recovery plan contemplates the backup system itself being affected is the question an entry like this raises.
Why it matters
A recovery plan is tested by whether it contemplates the backup system itself being affected. The breadth of connection a role requires becomes the breadth of what an effect reaches.
FAQ
Why are backup systems targeted?
Are backups alone enough?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).