CVE-2024-22022: Infoleak
Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22022?
CVE-2024-22022 has a CVSS score indicating a medium severity level, which highlights potential risk to confidentiality.
Who is affected by CVE-2024-22022?
CVE-2024-22022 affects users of Veeam Recovery Orchestrator versions below 7.0 with low-privileged roles.
How do I fix CVE-2024-22022?
To fix CVE-2024-22022, upgrade to Veeam Recovery Orchestrator version 7.0 or later.
What type of vulnerability is CVE-2024-22022?
CVE-2024-22022 is a privilege escalation vulnerability that allows low-privileged users to access sensitive information.
What are the potential impacts of CVE-2024-22022?
The potential impact of CVE-2024-22022 includes unauthorized access to the NTLM hash of the service account, which could lead to further exploitation.