Skip to main content

Vulnerability CVE-2023-27532 - Applying Patch


wolff.mateus
Forum|alt.badge.img+11

Recently we had a vulnerability on Veeam Backup & Replication called CVE-2023-27532.

So today, Iā€™m going to show how easy is update VBR and install the patch to correct this threat.

 

According with KB4424, we need to download the patch correctly to v11 or v12. In my case I going to update a v12 environment.

 

So, the first thing is download patch:

 

After that we only to unzip the downloaded file:

 

The installation is really simple. 

 

We only need next, next, finish:

 

I prefer to do not check box to update components automatically. We can do that as a final step after installation:

 

Just click finish:

 

Now we can open our VBR console and update the last component:

 

At the end we can check that Veeam Backup & Replication is on 12.0.0.1420 P20230223:

 

12 comments

Forum|alt.badge.img
  • Comes here often
  • 23 comments
  • March 9, 2023

Nicely done! Please post how you updated the other components that were excluded in the automatic update process.  Thanks.


Chris.Childerhose
Forum|alt.badge.img+21

Excellent write-up Mateus. Well done šŸ‘


wolff.mateus
Forum|alt.badge.img+11
  • Author
  • Veeam Vanguard
  • 534 comments
  • March 9, 2023
DerekA wrote:

Nicely done! Please post how you updated the other components that were excluded in the automatic update process.  Thanks.

Is one of the lasts images of the post. It is a simple step. You can check it here:

Server Components Upgrade - User Guide for VMware vSphere (veeam.com)

 

For this patch only VBR component is necessary.

 


dloseke
Forum|alt.badge.img+7
  • On the path to Greatness
  • 1447 comments
  • March 9, 2023

Thanks for this info.  Super helpful.  Fortunately, I did all (or most of) my upgrades and patching through the Service Provider Console.  Upgrades were a little hit and miss, but the patching went great!  Planning a blog post on that one as soon as I can find the time!


I have a small test environment with Veeam 12 and Hyper-V Windows 2022. Backup worked for about 3 weeks with Release 12. After installing P20230223 all my jobs failed with:

Failed to create VM recovery checkpoint (mode: Veeam application-aware processing) Details: Unable to perform application-aware processing because connection to the guest could not be established
Error: Unable to perform application-aware processing because connection to the guest could not be established
Processing finished with errors at 10.03.2023 08:35:33

For the test I'm using an NFR license, so it's not possible to open a case. After removing Veeam and reinstall GA it worked as before. Any idea what happened with this patch?


marcofabbri
Forum|alt.badge.img+13
  • On the path to Greatness
  • 990 comments
  • March 24, 2023

Stabz
Forum|alt.badge.img+8
  • On the path to Greatness
  • 351 comments
  • March 24, 2023

Hello guys just for your information if you apply some hardening on your servers, espescialy if you have change the ā€œDebug programā€ you could have the following error message ā€œNot All Privileges are Assigned to Caller error during upgrade/installā€

More information here: https://www.veeam.com/kb2465


wolff.mateus
Forum|alt.badge.img+11
  • Author
  • Veeam Vanguard
  • 534 comments
  • March 29, 2023

Just passing to say that you can vote on me for the blog of the March here:

Blog of the Month in March | Veeam Community Resource Hub

 

It is easy and you only need chose my post for that.


dloseke
Forum|alt.badge.img+7
  • On the path to Greatness
  • 1447 comments
  • March 30, 2023
marcofabbri wrote:

 

Boss man asked me on Monday about the exploit as it got new press with the release.  Told him it was patched nearly two weeks ago via the console.  Love it!


BertrandFR
Forum|alt.badge.img+8
  • Influencer
  • 527 comments
  • March 31, 2023

just to share with the community, i had the unpleasant surprise if you have some private fix deployed on your vbr. It could be not merged with the new patch, you should ask to the support to rebuild it.

@HannesK @Mildur Were you aware of that?


Mildur
Forum|alt.badge.img+12
  • Influencer
  • 1035 comments
  • March 31, 2023

Yes. We have some ideas to solve such issues for future updates.

https://forums.veeam.com/post482048.html#p482048

 

Best,

Fabian


Chris.Childerhose
Forum|alt.badge.img+21
Mildur wrote:

Yes. We have some ideas to solve such issues for future updates.

https://forums.veeam.com/post482048.html#p482048

 

Best,

Fabian

That is great šŸ‘