CVE-2024-40712: Path Traversal
Published Sep 7, 2024
·Updated
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
Affected Software
1 affected component
Veeam Veeam Backup \& Replication<12.2.0.334
Event History
Sep 7, 2024
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-40712?
CVE-2024-40712 has a medium severity rating due to its potential for local privilege escalation.
2
How do I fix CVE-2024-40712?
To fix CVE-2024-40712, upgrade to Veeam Backup & Replication version 12.2.0.334 or later.
3
Who is affected by CVE-2024-40712?
CVE-2024-40712 affects users of Veeam Backup & Replication versions prior to 12.2.0.334.
4
Can CVE-2024-40712 be exploited remotely?
No, CVE-2024-40712 requires local access and a low-privileged account to be exploited.
5
What type of vulnerability is CVE-2024-40712?
CVE-2024-40712 is a path traversal vulnerability that can lead to local privilege escalation.