logo

Veeam says critical flaw can't be abused to trash backups

ID: 9cc1fac0-056a-5d07-b137-ff08faf29bbe

STIX ID: report--9cc1fac0-056a-5d07-b137-ff08faf29bbe

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2024-05-23

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Veeam disclosed a critical vulnerability (CVE-2024-29849, rated 9.8) in its optional Backup Enterprise Manager component that allows attackers to log into the VBEM web interface as any user; Veeam states immutable backups and four-eyes authorization prevent deletion of backups. The vendor released VBEM 12.1.2.172 fixing this and three related CVEs (including an NTLM relay account-takeover issue), and recommends applying the patch or temporarily stopping/disabling VBEM services or uninstalling VBEM where not used.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.