Skip to content

Veeam Service Provider Console (VSPC) remote code execution.

Notifications You must be signed in to change notification settings

h3lye/CVE-2024-42448-RCE

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 

Repository files navigation

CVE-2024-42448-RCE

Veeam Service Provider Console (VSPC) remote code execution.

Download link here

Details:

is a critical vulnerability identified in the Veeam Service Provider Console (VSPC) with a CVSS score of 9.9.
This vulnerability allows for remote code execution (RCE).

About:

(files.zip) here you'll find the files and including but not limit to tcp packets captured during testing
some progress with IDA (which was unnecessary), but will be effective if you try to understand the root cause
and produce a working exploit.
every step is explained clearly with screenshots inside the process.pdf.
for educational purpose only.

A python script (CVE-2024-42448.py) which trigger the vulnerability and execute user supplied command
can also execute command on single and multiple targets(IP list) with multi-threading capability.

Download: here

About

Veeam Service Provider Console (VSPC) remote code execution.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published