Veeam released security updates for Veeam Service Provider Console (VSPC) to fix two vulnerabilities tracked as CVE-2024-42448 and CVE-2024-42449. The most severe issue, CVE-2024-42448, carries a CVSS 9.9 rating and can allow a remote authenticated attacker with access to VSPC management agents to execute code on VSPC servers. The second flaw, CVE-2024-42449, is rated CVSS 7.1 and can be exploited to obtain the NTLM hash of the VSPC server service account and delete files on the server.
Affected releases include VSPC 7.0.x, 8.0.x, and 8.1.x versions earlier than 8.1.0.21999. Exploitation requires the attacker to have authorization over abused agents on the targeted VSPC server, and Veeam has directed customers to upgrade impacted systems to version 8.1.0.21999 to remediate the issues.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Veeam released security updates for Veeam Service Provider Console to fix two vulnerabilities: critical remote code execution flaw CVE-2024-42448 and CVE-2024-42449, which can expose the NTLM hash of the VSPC server service account and allow file deletion. Affected versions include VSPC 7.0.X, 8.0.X, and 8.1.X versions older than 8.1.0.21999, and Veeam recommended upgrading to version 8.1.0.21999.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.