Veeam CVE Leads to Full Compromise - CVE-2023-27532

Опубликовано: 27 Июль 2026
на канале: Horizon3ai
528
2

Veeam Backup and Replication software is commonly used by enterprises for data protection and ransomware recovery. In 2023 a vulnerability affecting Veeam,CVE-2023-27532, was disclosed. This vulnerability enables attackers to dump highly privileged credentials used by Veeam for backup operations.

NodeZero has been able to successfully exploit the Veeam CVE in many environments. In the example below, NodeZero leveraged the Veeam vulnerability to fully compromise a client’s on-prem environment and AWS infrastructure.

To be clear, attack paths that NodeZero discovers are completely valid paths that an attacker could take, and in doing so, can completely lead to compromise. This is a real attack performed by NodeZero with no human penetration testers involved. The attack was executed safely against production systems that were not in a lab environment.

---------------------------------------------------------------------------------------------------
Website: https://www.horizon3.ai/
Twitter:   / horizon3ai  
LinkedIn:   / horizon3ai