Back to advisories
Critical
1 min read
Advisory: Exploitation of CVE-2023-27532 on Veeam by Ransomware Groups
Estate and Phobos Ransomware Groups have been exploiting the CVE-2023-27532 vulnerability in Veeam Backup & Replication for initial access.
Severity: CRITICAL
Published: July 5, 2024
Reference: WHNG-ADV-20240705-3624992A
CVE IDs: CVE-2023-27532
Critical Severity
This vulnerability requires immediate attention. Affected systems should be patched or mitigated as soon as possible.
Advisory: Exploitation of CVE-2023-27532 on Veeam by Ransomware Groups
Threat Overview
Estate and Phobos Ransomware Groups have been actively exploiting the CVE-2023-27532 vulnerability in Veeam Backup & Replication software.
Vulnerability Details
| Field | Value |
|---|---|
| CVE ID | CVE-2023-27532 |
| CVSS Score | 7.5 (High) |
| Affected Product | Veeam Backup & Replication |
Immediate Actions Required
- Patch Immediately: Update Veeam to the latest version
- Network Segmentation: Isolate backup infrastructure
- Access Control: Restrict access to Veeam management interfaces
- Credential Rotation: Change all passwords stored in Veeam
WhiteHat NG Security Advisory