Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Threats and Vulnerabilities - Critical Vulnerabilities Found in Veeam Service Provider Console
Threats and Vulnerabilities Latest News News & Analysis Threat Intelligence

Critical Vulnerabilities Found in Veeam Service Provider Console

Kirsten DoyleBy Kirsten DoyleDecember 5, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Critical Vulnerabilities Found in Veeam Service Provider Console
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Two critical vulnerabilities (CVE-2024-42448 and CVE-2024-42449) have been identified in Veeam Service Provider Console (VSPC), prompting an urgent call for users to update their systems.

According to Veeam’s latest security advisory, the vulnerabilities affect all builds of VSPC versions 7 and 8. The first flaw (CVE-2024-42448) allows for remote code execution (RCE) on the server when exploited by an authorized management agent, carrying a CVSS score of 9.9. The second issue (CVE-2024-42449) exposes the system to NTLM hash leaks and file deletions, with a CVSS score of 7.1.

Veeam has confirmed that these vulnerabilities were discovered during internal testing and stressed that there are no available mitigations other than upgrading to version 8.1.0.21999 or later.

Service providers using VSPC are strongly advised to apply the patch immediately. Unsupported versions should be upgraded to the latest release to ensure continued security.

Attractive Targets

The recent Veeam vulnerabilities underscore the ongoing challenges managed service providers (MSPs) face in vulnerability and patch management, comments Elad Luz, Head of Research at Oasis Security.  MSPs often depend heavily on third-party tools to manage client data and maintain business continuity. When these tools, like Veeam, are compromised—especially through vulnerabilities enabling remote code execution (RCE)—critical backup systems become attractive targets for cybercriminals.

Luz says this risk is particularly severe in sectors such as finance, healthcare, and legal services, where safeguarding sensitive data is paramount.

Proactively investing in secure backup and recovery solutions is key to preventing ransomware attacks and data breaches. A compromised backup system can hinder an organization’s ability to recover, leaving both live and backup systems vulnerable to exploitation. To mitigate these risks, organizations must prioritize timely patching, adopt a multi-layered security strategy, and implement effective incident response plans, thereby reducing their exposure to cyber threats, explains Luz.

Severe Operational, Security Risks

Jason Soroko, Senior Fellow at Sectigo, adds that the impact of these vulnerabilities is substantial. CVE-2024-42448, with a critical CVSS score of 9.9 out of 10, allows for remote code execution (RCE) on the VSPC server machine from an authorized management agent machine. “This means that an attacker who gains control of a management agent could execute arbitrary code on the server, potentially leading to full system compromise, data theft, or service disruption.   Teams should immediately prioritize applying the security updates provided by Veeam.  Delaying this action exposes your infrastructure to potential attacks that could have significant operational and security implications.”

“CVE-2024-42449 allows attackers to extract NTLM hashes and delete files, potentially escalating privileges within the system,” adds Mayuresh Dani, Manager of Security Research at Qualys. “These methods are commonly exploited by initial access brokers. Organizations should update to VSPC version 8.1.0.21999 to protect their systems and ensure business continuity.”

This incident also highlights the importance of securing APIs, which are integral to managing backup and recovery solutions, explains Eric Schwake, Director of Cybersecurity Strategy at Salt Security. “A robust API security strategy, including strong authentication, authorization, and continuous monitoring, is vital to safeguarding against unauthorized access and potential cyberattacks.”

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

June 2, 20263 Mins Read

How EM is boosting the career trajectory of VM analysts

May 19, 20266 Mins Read

Microsoft patches 138 vulnerabilities as AI-driven discovery accelerates

May 14, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}