Saturday, February 8, 2025
HomeCVE/vulnerabilityVeeam Critical Flaws Let Attackers Execute Remote Code and Steal NTLM Hashes

Veeam Critical Flaws Let Attackers Execute Remote Code and Steal NTLM Hashes

Published on

SIEM as a Service

Follow Us on Google News

Veeam, a Global Leader in Data Protection, issued hotfixes to address four vulnerabilities affecting the Veeam ONE IT infrastructure monitoring and analytics platform.

Two vulnerabilities are classified as ‘critical,’ while the other two are classified as ‘medium severity’ flaws.

The critical flaws allow remote code execution and steal NTLM Hashes, and the medium-severity issues involve user interaction and have a lesser impact.

Critical Flaws Addressed

A critical vulnerability tracked as CVE-2023-38547 in Veeam ONE with a CVSS base score of 9.9 allows an unauthenticated user to obtain information about the SQL server connection used by Veeam ONE to access its configuration database, an advisory published today stated.

“This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database,” the company said in its advisory.

CVE-2023-38547 affected Veeam ONE Versions 11, 11a, 12

Because of a flaw in Veeam ONE identified as CVE-2023-38548 with a CVSS base score of 9.8, anyone with access to the Veeam ONE Web Client can get the NTLM hash of the account used by the Veeam ONE Reporting Service.

CVE-2023-38548 Affected Veeam versions ONE 12.

Medium Severity Flaws Addressed

A flaw classified as CVE-2023-38549 with a CVSS base score of 4.5 in Veeam ONE permits a user with the Veeam ONE Power user role to gain the access token of a user with the Veeam ONE Administrator role using XSS.  

“The criticality of this vulnerability is reduced as it requires interaction by a user with the Veeam ONE Administrator role,” the company said.

Affected versions are Veeam ONE 11, 11a, 12.

In Veeam ONE, a vulnerability classified as CVE-2023-41723 and a CVSS base score of 4.3 permits the Dashboard Schedule to be viewed by a user with the Veeam ONE Read-Only User role.

“The criticality of this vulnerability is reduced because the user with the Read-Only role is only able to view the schedule and cannot make changes,” the company said.

Affected versions are Veeam ONE 11, 11a, 12.

Document
FREE Webinar

Webinar on Cyber Resilience for Financial Sector

Ensure your Cyber Resiliance with the recent wave of cyber-attacks targeting the financial services sector. Almost 60% respondents not confident to recover fully from a cyber attack.

Patches Released

For the following versions, there is a patch available that fixes these vulnerabilities:

  • Veeam ONE 12 P20230314 (12.0.1.2591)
  • Veeam ONE 11a (11.0.1.1880)
  • Veeam ONE 11 (11.0.0.1379)

The hotfix installation instructions provided by Veeam require administrators to stop monitoring and reporting services, replace files, and restart services.

Patch Manager Plus: Patch over 850 third-party applications quickly. Try a free trial to ensure 100% security.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Autonomous LLMs Reshaping Pen Testing: Real-World AD Breaches and the Future of Cybersecurity

Large Language Models (LLMs) are transforming penetration testing (pen testing), leveraging their advanced reasoning...

Securing GAI-Driven Semantic Communications: A Novel Defense Against Backdoor Attacks

Semantic communication systems, powered by Generative AI (GAI), are transforming the way information is...

Cybercriminals Target IIS Servers to Spread BadIIS Malware

A recent wave of cyberattacks has revealed the exploitation of Microsoft Internet Information Services...

Hackers Leveraging Image & Video Attachments to Deliver Malware

Cybercriminals are increasingly exploiting image and video files to deliver malware, leveraging advanced techniques...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Microsoft Sysinternals 0-Day Vulnerability Enables DLL Injection Attacks on Windows

A critical zero-day vulnerability has been discovered in Microsoft Sysinternals tools, posing a serious security threat...

7-Zip 0-Day Flaw Added to CISA’s List of Actively Exploited Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical 0-day vulnerability...

Logsign Vulnerability Allows Remote Attackers to Bypass Authentication

A critical security vulnerability has been identified and disclosed in the Logsign Unified SecOps...