CVE-2024-42019: Veeam One

High severity, CVSS 8.0. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication.

Affected products

  • Veeam One: before 12.2.0.4093 (fixed in 12.2.0.4093)

Published 2024-09-07. Last modified 2026-06-17.