1080*80 ad

Veeam v12.3.2.4165 Patch

Urgent Security Alert: Patch Your Veeam Environment for Critical Vulnerability CVE-2024-29855

Veeam has released a critical security patch to address a high-severity vulnerability in Veeam Backup & Replication. This update resolves a critical security flaw in the Veeam Backup Enterprise Manager (VBEM) component and includes numerous stability and performance enhancements. All administrators are strongly advised to apply this patch immediately to safeguard their data infrastructure.

The new patch addresses version 12.1.2.172 of Veeam Backup & Replication and is designated as P20240529. Its primary purpose is to fix a critical vulnerability that could compromise your entire backup environment.

Understanding the Critical Vulnerability: CVE-2024-29855

The central focus of this patch is the resolution of CVE-2024-29855, a broken access control vulnerability with a high severity score.

Here’s what you need to know:

  • Impact: This flaw allows an unauthenticated remote attacker to log into the Veeam Backup Enterprise Manager web interface as any user. This means an attacker requires no prior access or credentials to gain control.
  • Component Affected: The vulnerability is specific to the Veeam Backup Enterprise Manager (VBEM). If you do not have this component installed and in use, your environment is not exposed to this specific threat. However, the cumulative nature of the patch still makes it highly recommended.
  • Risk: A successful exploit could grant an attacker complete control over backup jobs, allowing them to view, modify, or even delete critical backup data, restore sensitive files, or disrupt recovery operations.

Given the ease of exploitation and the potential for catastrophic data loss or breach, patching this vulnerability should be your top priority.

Beyond Security: Additional Fixes and Enhancements

While the security fix is the most urgent reason to update, the P20240529 patch also delivers a range of important bug fixes and stability improvements. These cumulative updates enhance the reliability of your backup operations.

Key enhancements include:

  • Tape and GFS Jobs: Resolves issues where Grandfather-Father-Son (GFS) tape jobs could incorrectly identify a backup chain as incomplete, leading to failed runs. It also fixes problems with synthetic full backups on certain tape libraries.
  • Object Storage: Addresses bugs related to immutability in Dell Data Domain and HPE StoreOnce repositories. The patch also improves interaction with object storage repositories that use single-region AWS STS endpoints.
  • Storage and Platform Support: Fixes an issue where rescanning a NetApp ONTAP storage system could fail. It also resolves errors related to using Veeam VHR tools with Linux Hardened Repositories.
  • General Reliability: Corrects various issues, including incorrect license usage calculations after upgrading, UI errors in the console, and performance problems with certain SQL Server transaction log backups.

Actionable Steps: How to Secure Your Veeam Environment Now

Protecting your environment is straightforward. Follow these steps to apply the necessary update and secure your systems.

  1. Confirm Your Version: This patch is specifically for Veeam Backup & Replication version 12.1.2.172. You can check your current version by opening the Veeam console and navigating to Help > About.
  2. Verify Use of Enterprise Manager: The critical vulnerability (CVE-2024-29855) only impacts systems with Veeam Backup Enterprise Manager deployed. Identify if this component is active in your environment.
  3. Download and Install the Patch: Download the patch (KB4510: Veeam Backup & Replication 12.1.2 P20240529) directly from the official Veeam website.
  4. Follow Best Practices for Installation: Before running the installer, stop all Veeam services to ensure a clean update process. Execute the installer with administrative privileges on your Veeam Backup & Replication server. If you use Enterprise Manager, you must also install the patch on that server.
  5. Verify the Update: After the installation is complete, re-open the console and check the version in Help > About. The new build number should be 12.1.2.172 P20240529.

Proactive security is non-negotiable when it comes to your organization’s data backups. This vulnerability represents a clear and present danger to unprotected systems. Do not delay—update your Veeam environment today to ensure your data remains secure, available, and recoverable.

Source: https://nolabnoparty.com/patch-veeam-v12-3-2-4165/

900*80 ad

      1080*80 ad