CVE-2024-39718: Input Validation
Published Sep 7, 2024
·Updated
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
Affected Software
1 affected component
Veeam Veeam Backup \& Replication>=12.0.0.1402<12.2.0.334
Event History
Sep 7, 2024
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-39718?
CVE-2024-39718 has a high severity rating due to its potential for remote file deletion by low-privileged users.
2
How does CVE-2024-39718 work?
CVE-2024-39718 exploits improper input validation to allow attackers to remotely remove files using the service account's permissions.
3
How do I fix CVE-2024-39718?
To mitigate CVE-2024-39718, upgrade Veeam Backup & Replication to a version higher than 12.2.0.334.
4
Who is affected by CVE-2024-39718?
CVE-2024-39718 affects users of Veeam Backup & Replication versions between 12.0.0.1402 and 12.2.0.334.
5
What are the potential impacts of CVE-2024-39718?
The potential impacts of CVE-2024-39718 include unauthorized file removals, data loss, and service disruption.