Back to advisories
Critical
1 min read

Advisory: Exploitation of CVE-2023-27532 on Veeam by Ransomware Groups

Estate and Phobos Ransomware Groups have been exploiting the CVE-2023-27532 vulnerability in Veeam Backup & Replication for initial access.

Critical Severity

This vulnerability requires immediate attention. Affected systems should be patched or mitigated as soon as possible.

Advisory: Exploitation of CVE-2023-27532 on Veeam by Ransomware Groups

Threat Overview

Estate and Phobos Ransomware Groups have been actively exploiting the CVE-2023-27532 vulnerability in Veeam Backup & Replication software.

Vulnerability Details

Field Value
CVE ID CVE-2023-27532
CVSS Score 7.5 (High)
Affected Product Veeam Backup & Replication

Immediate Actions Required

  1. Patch Immediately: Update Veeam to the latest version
  2. Network Segmentation: Isolate backup infrastructure
  3. Access Control: Restrict access to Veeam management interfaces
  4. Credential Rotation: Change all passwords stored in Veeam

WhiteHat NG Security Advisory