CVE-2024-40711: Veeam Backup and Replication Deserialization Vulnerability
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
Other sources
Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40711?
CVE-2024-40711 is classified as a critical vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2024-40711?
To fix CVE-2024-40711, it is recommended to update Veeam Backup and Replication to the latest patched version.
What type of vulnerability is CVE-2024-40711?
CVE-2024-40711 is a deserialization of untrusted data vulnerability that can be exploited for remote code execution.
Can CVE-2024-40711 be exploited remotely?
Yes, CVE-2024-40711 can be exploited remotely by an unauthenticated user.
Which versions of Veeam Backup and Replication are affected by CVE-2024-40711?
CVE-2024-40711 affects Veeam Backup and Replication versions between 12.0.0.1420 and 12.2.0.334.