High severity8.8NVD Advisory· Published Dec 4, 2024· Updated Jun 17, 2026
CVE-2024-42452
CVE-2024-42452
Description
A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges. The vulnerability exists because remote calls bypass permission checks, leading to full system compromise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*range: >=12.0.0.1402,<12.3.0.310
- (no CPE)
- (no CPE)range: 12.2
Patches
Vulnerability mechanics
References
1- www.veeam.com/kb4693nvdVendor Advisory
News mentions
0No linked articles in our index yet.