#1 Global Leader in Data Resilience

Vulnerability Scanner Detection Related to CVE-2024-7264

KB ID: 4718
Product: Veeam Backup & Replication
Published: 2025-04-02
Last Modified: 2025-04-02
mailbox
Get weekly article updates
By subscribing, you are agreeing to have your personal information managed in accordance with the terms of Veeam's Privacy Notice.

Cheers for trusting us with the spot in your mailbox!

Now you’re less likely to miss what’s been brewing in our knowledge base with this weekly digest

error icon

Oops! Something went wrong.

Please, try again later.

Support Statement

This Veeam KB article was created to address customers' concerns regarding the detection of the libcurl library by their security software on VMware Backup Proxies, where the VMware VDDK package is installed. Libcurl is a component of VMware VDDK (Virtual Disk Development Kit), which Veeam Backup & Replication redistributes to enable the protection of VMware vSphere environments. Veeam Backup & Replication deploys the VMware VDDK package on VMware Backup Proxies for data movement.

Veeam Backup & Replication is not impacted by the vulnerability within the libcurl library included with VMware VDDK because Veeam Backup & Replication utilizes a separate dedicated curl library, which was updated to version 8.10.1 in Veeam Backup & Replication version 12.3. The libcurl file within the VMware VDDK package is only present because it is included as part of the VDDK library as a whole, and VMware has advised that "There is no risk of data leakage since VDDK does not expose curl's CURLINFO_CERTINFO, which is the component involved in the vulnerability." For this same reason, older versions of Veeam Backup & Replication that may have included old curl libraries are not affected, as Veeam Backup & Replication does not expose curl's CURLINFO_CERTINFO.

In July of 2024, a vulnerability (CVE-2024-7264) involving curl and libcurl was made public. Full details regarding this vulnerability can be found in the articles listed below.
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Spelling error in text

Thank you!

Thank you!

Your feedback has been received and will be reviewed.

Oops! Something went wrong.

Please, try again later.

You have selected too large block!

Please try select less.

KB Feedback/Suggestion

This form is only for KB Feedback/Suggestions, if you need help with the software open a support case

By submitting, you are agreeing to have your personal information managed in accordance with the terms of Veeam's Privacy Notice.
Verify your email to continue your product download
We've sent a verification code to:
  • Incorrect verification code. Please try again.
An email with a verification code was just sent to
Didn't receive the code? Click to resend in sec
Didn't receive the code? Click to resend
Thank you!

Thank you!

Your feedback has been received and will be reviewed.

error icon

Oops! Something went wrong.

Please, try again later.