Exploited Known exploited (KEV) Ransomware use CVE-2024-40711

Veeam Backup and Replication deserialization (CVE-2024-40711) — take the means of restoring and there is nowhere to restore to

Veeam Backup & Replication Added to KEV Oct 17, 2024 Federal remediation due 2024-11-07

A deserialization vulnerability in backup software, described as allowing an unauthenticated user to perform remote code execution. Backup is the means of returning from harm, and taking it removes the premise of recovery.

Key facts

  • CVE IDCVE-2024-40711
  • Affected (vendor / product)Veeam Backup & Replication
  • CWECWE-502
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2024-11-07 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected product is Veeam Backup & Replication, classified as deserialization of untrusted data.
  • An unauthenticated user is described as able to perform remote code execution, and use in ransomware campaigns is known.
  • Backup is the means of returning from harm, so taking it removes the premise of recovery.
  • A backup system must connect across the whole of an organization systems, and that breadth is also the breadth of any effect.
  • Added October 17, 2024 with a due date of November 7, 21 days later.

1Cutting off the way back first

When data is encrypted or lost, an organization turns to its backups. That is exactly why the backup system itself becomes a target: with the means of recovery unavailable, the remaining options narrow.

Where a business system is affectedWhere the backup system is affected
The means of recovery remainsWhat you would restore to may be lost
Stopping and restoring is a live optionThe range of options narrows
Harm may stay within that systemIt reaches recovery as a whole

Backup is an unobtrusive system in normal times. Its running is taken for granted, and it tends to slip down the list for updates. That this entry is marked as known in ransomware campaigns is not unrelated to that position.

2The class of flaw

  1. 1The mechanismRestoring data converted for storage or transmission back to its original structure
  2. 2During restorationThe structure is rebuilt following the content received
  3. 3Where trouble arisesWhere what arrives from an untrusted party is restored as it stands
  4. 4The condition hereAn unauthenticated user may perform remote code execution

This site has a separate article devoted to this class. What stands out here is that no authentication is required: someone holding no credentials, merely positioned to send requests to this system, is enough.

3How backup is placed

Grouping for this entry across the records this site holds as of 2026-09-04Within business platforms32 unpublished entries with known ransomware use
Due date21 daysAdded October 17, 2024, due November 7
Entries of this class as of 2026-09-0465 classified as deserialization of untrusted dataCounted across the unpublished records this site holds

A backup system cannot do its job without connecting across the whole of an organization systems. That breadth of connection is also the breadth of what an effect can reach. This site covers the same shape for tools placed there to support and operate, where breadth required by a role becomes a weakness.

4Checking in normal times

Having backups and being able to restore from them are different things. Equally, a system running and that system itself being protected are different things. Whether a recovery plan contemplates the backup system itself being affected is the question an entry like this raises.

Why it matters

A recovery plan is tested by whether it contemplates the backup system itself being affected. The breadth of connection a role requires becomes the breadth of what an effect reaches.

FAQ

Why are backup systems targeted?
With the means of recovery unavailable, the remaining options narrow. It amounts to cutting off the way back first.
Are backups alone enough?
Having backups and being able to restore are different things, and a system running and that system being protected are different things too.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#Backup#Deserialization
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.