#VU101171 Permissions, Privileges, and Access Controls in Backup & Replication - CVE-2024-40717
Published: December 3, 2024
Backup & Replication
Veeam
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. A remote user with a role assigned in the Users and Roles settings on the backup server to execute a script with elevated privileges by configuring it as a pre-job or post-job task, thereby causing the script to be executed as LocalSystem.