Low-Privileged User Can Exploit Insecure Deserialization to Delete Any File with Service Account Privileges
CVE-2024-42455
8.1HIGH
What is CVE-2024-42455?
A vulnerability within Veeam Backup & Replication enables low-privileged users to connect to remoting services and exploit weaknesses in the deserialization process. An attacker can send a serialized temporary file collection that is insufficiently validated, allowing them to delete any file on the system with the privileges of the service account. This flaw highlights the critical need for robust validation mechanisms during the deserialization process to prevent unauthorized actions on sensitive files and data.
Affected Version(s)
Backup & Replication 12.2