Vulnerability Description
DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Veeam | Veeam Agent For Windows | >= 6.0.0.959, < 6.3.0.177 |
Related Weaknesses (CWE)
References
- https://www.veeam.com/kb4693Vendor Advisory
FAQ
What is CVE-2024-45207?
CVE-2024-45207 is a vulnerability with a CVSS score of 7.0 (HIGH). DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker plac...
How severe is CVE-2024-45207?
CVE-2024-45207 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-45207?
Check the references section above for vendor advisories and patch information. Affected products include: Veeam Veeam Agent For Windows.