Loading...
Loading...
A vulnerability in the Veeam Updater component allows a local user to elevate their privileges and gain root-level access to the underlying operating system. Severity: HighCVSS Score: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NSource: Reported through HackerOne by skydesperados. Impacted Components: Veeam Software Appliance (Linux-based Veeam Backup & Replication Server) Veeam Infrastructure Appliance
This vulnerability is resolved starting in the Veeam Updater component version 12.3.0.65. Automatic Update Deployment — For most users, no action is needed, as the Veeam Updater component installs the fix automatically during its automatic update check. Manual Update Deployment — If the Veeam Software Appliance or any Veeam Infrastructure Appliance is unable to reach either repository.veeam.com or a local mirror repository, the fix must be applied manually with assistance from Veeam Support, or temporary internet access to the update server must be configured. For more information about Veeam Appliance Update configuration, review the product user guide:Veeam Backup & Replication User Guide: Updating Veeam Appliances
Click on a version to see all relevant bugs
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.