A vulnerability allowing remote code execution (RCE) by authenticated domain users.
Severity: Critical
CVSS v3.1 Score: 9.9AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: Reported by Piotr Bazydlo of watchTowr.
Veeam Backup & Replication 12.3.0.310 and all earlier version 12 builds.
Note: Unsupported product versions are not tested, but are likely affected and should be considered vulnerable.
For deployments currently running Veeam Backup & Replication 12.3 (build 12.3.0.310), a hotfix to resolve this vulnerability has been developed and is intended for customers who cannot immediately update to version 12.3.1.
Note: This hotfix can only be installed if the current Veeam Backup & Replication 12.3 deployment has no other hotfixes installed, as it may overwrite earlier hotfixes. If other hotfixes for version 12.3 have been installed, the deployment must be updated to 12.3.1.
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case