Successful exploitation of CVE-2024-40711 could lead to remote code execution
Summary
Successful exploitation of CVE-2024-40711 could lead to remote code execution
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
In September 2024, Veeam issued a security bulletin addressing one critical and five high severity vulnerabilities in their Backup & Replication product, including CVE-2024-40711. These vulnerabilities were initially covered in the cyber alert CC-4542.
The NHS England National CSOC is now aware of reports that CVE-2024-40711 is under active exploitation by ransomware groups and is issuing this high severity Cyber Alert in response.
CVE-2024-40711 is a critical 'deserialisation of untrusted data' vulnerability with a CVSSv3 score of 9.8. If exploited, an unauthenticated attacker could achieve remote code execution (RCE).
Remediation advice
Affected organisations must review the Veeam Security Bulletin (September 2024) KB4649 and update Veeam Backup & Replication to version 12.2 (or above) as a matter of urgency.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 11 October 2024 11:21 am