Vulnerabilities in Veeam

74 results
Vexday analysis

O portfólio de vulnerabilidades da Veeam apresenta uma taxa de exploração ativa 3,1 vezes acima da média geral do catálogo CISA KEV, o que indica risco operacional elevado mesmo com volume total moderado de 72 CVEs. A CVE-2024-40711, atualmente a falha mais perigosa em exploração ativa, registra EPSS de 0,8819 — valor que aponta alta probabilidade de exploração em ambiente real e deve ser tratado com prioridade máxima de remediação. O tipo de falha mais recorrente é CWE-94 (injeção de código), padrão que tende a viabilizar execução remota e comprometimento profundo de sistemas de backup, categoria de ativo historicamente visada por agentes de ransomware. Com 25 CVEs críticas, 6 com PoC pública disponível e 5 surgidas nos últimos 90 dias, o cenário exige monitoramento contínuo e aplicação rigorosa de patches.

CVE-2024-40713HIGHA vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor AutheEPSS 0.3%CVE-2024-42021HIGHAn improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.EPSS 0.3%CVE-2024-40712HIGHA path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege esEPSS 0.3%CVE-2024-42022HIGHAn incorrect permission assignment vulnerability allows an attacker to modify product configuration files.EPSS 0.3%CVE-2024-42451HIGHA vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by caEPSS 0.3%CVE-2024-45206MEDIUMA vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts ofEPSS 0.2%CVE-2025-24287MEDIUMA vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with eleEPSS 0.2%CVE-2026-21672HIGHA vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.EPSS 0.2%CVE-2024-29853HIGHAn authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.EPSS 0.2%CVE-2024-40709HIGHA missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.EPSS 0.2%CVE-2024-45207HIGHDLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searchEPSS 0.2%CVE-2026-21709MEDIUMA vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.EPSS 0.2%CVE-2025-48982HIGHThis vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restEPSS 0.2%CVE-2026-32996HIGHThis vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.EPSS 0.2%