CVE-2024-40711

9.8CRITICAL

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

公開日: 9/7/2024更新日: 10/30/2025

CISA既知の悪用された脆弱性

Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.

必要な対応:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

期限:

2024-11-07

既知のランサムウェア使用

説明

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

AI分析AIによる分析

影響を受ける製品

veeamveeam_backup_\&_replication

参照