#VU101175 Deserialization of Untrusted Data in Backup & Replication - CVE-2024-42455
Published: December 3, 2024
Backup & Replication
Veeam
Description
The vulnerability allows a remote user to delete arbitrary files on the system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote user with a role assigned in the Users and Roles settings on the backup server can connect to remote services and exploit insecure deserialization by sending a serialized temporary file collection, thereby enabling the deletion of any file on the system with service account privileges.