PSA: If you use #Veeam Backup & Replication (very common), upgrade. Especially if you face server to internet.

Screenshot from Code White, the API lets you remotely request Windows admin credentials for some reason, no auth request.

In their advisory Veeam claimed these are encrypted... it's base64 (lololol)

#CVE202327532 https://www.veeam.com/kb4424

KB4424: CVE-2023-27532

Vulnerability CVE-2023-27532 in a Veeam Backup & Replication component allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.

Veeam Software
@GossiTheDog I don’t understand why anyone would expose their backup system to the Internet.

@deepthoughts10 @GossiTheDog I think #attackSurface reduction is not well understood by many non #security folks as well as security folks.

You don’t have to fix so often what is not exposed
Try to be lazy and don’t expose it right from the start