CVE-2024-22022
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Feb 7, 2024
Updated: Feb 15, 2024
Summary
CVE-2024-22022 is a newly disclosed vulnerability that grants low-privileged Veeam Recovery Orchestrator users the ability to retrieve the NTLM hash of the service account employed by the Veeam Orchestrator Server Service. This shortcoming can potentially be exploited by attackers to gain elevated access, posing a significant risk to affected systems. It's crucial for organizations using Veeam Recovery Orchestrator to apply the necessary patches as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Veeam