CVE-2024-45207
Last modified
CVE-2024-45207 is a vulnerability of currently unknown severity. DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Veeam | Veeam Agent For Windows | >= 6.0.0.959, < 6.3.0.177 |
References
- https://www.veeam.com/kb4693Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-45207?
How severe is CVE-2024-45207?
How do I fix CVE-2024-45207?
Are you affected by CVE-2024-45207?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
