Skip to main content

YARA Rule for CVE-2024-3094


dips
Forum|alt.badge.img+7

Hi Folks,

Following on from the news regarding a backdoor in the Linux library xz, a Yara Rule is now available that can be used in Veeam 12.1 if you do not utilise a vulnerability scanner in your environment. Great way to check by leveraging Veeam to do the scanning for you. 

There is more info about the vulnerability on the post by @JMeixner :

https://community.veeam.com/cyber-security-space-95/severe-vulnarabiity-in-linux-library-xz-7151

Yara Rule can be found here: https://github.com/Neo23x0/signature-base/blob/master/yara/bkdr_xz_util_cve_2024_3094.yar

 

Comment