Vulnerability record · CVE-2024-40711 · published 7 September 2024
CVE-2024-40711: Veeam Backup & Replication deserialization flaw allows unauthenticated RCE
Veeam · Veeam Backup \& Replication
Veeam Backup & Replication contains a deserialization of untrusted data vulnerability (CWE-502) that permits an unauthenticated attacker to execute arbitrary code remotely. The flaw is rated CVSS 9.8 critical and has been exploited in ransomware campaigns, making it a high-priority target for defenders.
Description
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated RCE, active exploitation in ransomware campaigns, and CISA KEV listing make this an urgent risk.
What it is
Veeam Backup & Replication contains a deserialization of untrusted data vulnerability (CWE-502) that permits an unauthenticated attacker to execute arbitrary code remotely. The flaw is rated CVSS 9.8 critical and has been exploited in ransomware campaigns, making it a high-priority target for defenders.
Impact
An attacker can achieve remote code execution without authentication, potentially taking full control of the backup server and the data it manages. This can lead to data theft, ransomware deployment, and disruption of backup and recovery operations.
Attack surface
The vulnerability is reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), as indicated by the CVSS vector. Any exposed Veeam Backup & Replication service is a potential entry point.
Exploitation
CVE-2024-40711 is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and public exploit code is referenced. EPSS probability is 0.90369 (99.79th percentile), indicating very high likelihood of exploitation.
What to do
- Apply the vendor patch or mitigation instructions from Veeam KB4649 immediately.
- If patching is not possible, discontinue use of the product or isolate it from untrusted networks per CISA guidance.
- Restrict network access to Veeam Backup & Replication services to trusted management networks only.
- Monitor for and block known indicators of compromise associated with ransomware groups exploiting this flaw.
- Ensure backups are immutable and offline to prevent ransomware encryption.
Detection
- Monitor network traffic for unexpected connections to Veeam Backup & Replication ports from untrusted sources.
- Review Veeam logs for deserialization errors or unusual process creation events on backup servers.
- Hunt for known exploitation artifacts or indicators published by security researchers and CISA.
- Enable and centralize logging for Veeam services and correlate with endpoint detection alerts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-40711 to the Known Exploited Vulnerabilities catalog on 17 October 2024 as "Veeam Backup and Replication Deserialization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 November 2024.
Ransomware crews whose documented playbooks reference this CVE: