Veeam says critical flaw can't be abused to trash backups
ID: 9cc1fac0-056a-5d07-b137-ff08faf29bbe
STIX ID: report--9cc1fac0-056a-5d07-b137-ff08faf29bbe
Feed Name: The Register (Security)
Veeam disclosed a critical vulnerability (CVE-2024-29849, rated 9.8) in its optional Backup Enterprise Manager component that allows attackers to log into the VBEM web interface as any user; Veeam states immutable backups and four-eyes authorization prevent deletion of backups. The vendor released VBEM 12.1.2.172 fixing this and three related CVEs (including an NTLM relay account-takeover issue), and recommends applying the patch or temporarily stopping/disabling VBEM services or uninstalling VBEM where not used.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
