CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
12.7%
Vulnerability (CVE-2022-26503) in Veeam Agent for Microsoft Windows allows local privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code with LOCAL SYSTEM privileges.
Severity: High CVSS v3 score: 7.8
Veeam Agent for Microsoft Windows uses Microsoft .NET data serialization mechanisms. A local user may send malicious code to the network port opened by Veeam Agent for Microsoft Windows Service (TCP 9395 by default), which will not be deserialized properly.
This vulnerability is fixed in the following Veeam Agent for Microsoft Windows patched releases:
Notes:
If a Auto-update backup agent is enabled, the Veeam Agent for Microsoft Windows deployments will be updated automatically. Otherwise, the update must be manually triggered in the Veeam Backup & Replication console.
This vulnerability was reported by Nikita Petrov (Positive Technologies).
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
Vendor | Product | Version | CPE |
---|---|---|---|
veeam | veeam_backup_for_google_cloud | 5.0 | cpe:2.3:a:veeam:veeam_backup_for_google_cloud:5.0:*:*:*:*:*:*:* |
veeam | veeam_backup_for_google_cloud | 4.0 | cpe:2.3:a:veeam:veeam_backup_for_google_cloud:4.0:*:*:*:*:*:*:* |
veeam | veeam_backup_for_google_cloud | 3.0.2 | cpe:2.3:a:veeam:veeam_backup_for_google_cloud:3.0.2:*:*:*:*:*:*:* |
veeam | veeam_backup_for_google_cloud | 2.2 | cpe:2.3:a:veeam:veeam_backup_for_google_cloud:2.2:*:*:*:*:*:*:* |
veeam | veeam_backup_for_google_cloud | 2.1 | cpe:2.3:a:veeam:veeam_backup_for_google_cloud:2.1:*:*:*:*:*:*:* |
veeam | veeam_backup_for_google_cloud | 2.0 | cpe:2.3:a:veeam:veeam_backup_for_google_cloud:2.0:*:*:*:*:*:*:* |
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
12.7%