Advisory 78

Advisory 78: VEEAM Releases Security Updates for Multiple Products 

Release Date: 5th of February 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

What is it?

Veeam released security updates to address vulnerabilities in multiple products. A vulnerability in the Veeam Updater component allows an attacker to use a Man-in-the-Middle attack to execute arbitrary code on the affected appliance server with root-level permissions.
CERTVU encourages all System administrators to review the following advisory and apply necessary updates. 

Product: Veeam Backup for Salesforce
Veeam Backup for Nutanix AHV
Veeam Backup for AWS
Veeam Backup for Microsoft Azure
Veeam Backup for Google Cloud
Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization

References

1.    https://www.veeam.com/kb4712?utm_source=feedotter&utm_medium=email&utm_campaign=FO-02-04-2025&utm_content=httpswwwveeamcomkb4712