Veeam Backup and Replication software is commonly used by enterprises for data protection and ransomware recovery. In 2023 a vulnerability affecting Veeam,CVE-2023-27532, was disclosed. This vulnerability enables attackers to dump highly privileged credentials used by Veeam for backup operations.
NodeZero has been able to successfully exploit the Veeam CVE in many environments. In the example below, NodeZero leveraged the Veeam vulnerability to fully compromise a client’s on-prem environment and AWS infrastructure.
To be clear, attack paths that NodeZero discovers are completely valid paths that an attacker could take, and in doing so, can completely lead to compromise. This is a real attack performed by NodeZero with no human penetration testers involved. The attack was executed safely against production systems that were not in a lab environment.
---------------------------------------------------------------------------------------------------
Website: https://www.horizon3.ai/
Twitter: / horizon3ai
LinkedIn: / horizon3ai