Operational Defect Database

BugZero found this defect 800 days ago.

Veeam | kb4289

CVE-2022-26503

Last update date:

3/18/2022

Affected products:

Veeam Agent for Microsoft Windows

Affected releases:

2.2

Fixed releases:

No fixed releases provided.

Description:

Challenge

Vulnerability (CVE-2022-26503) in Veeam Agent for Microsoft Windows allows local privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code with LOCAL SYSTEM privileges. Severity: High CVSS v3 score: 7.8

Cause

Veeam Agent for Microsoft Windows uses Microsoft .NET data serialization mechanisms. A local user may send malicious code to the network port opened by Veeam Agent for Microsoft Windows Service (TCP 9395 by default), which will not be deserialized properly.

Solution

This vulnerability is fixed in the following Veeam Agent for Microsoft Windows patched releases:

More Information

This vulnerability was reported by Nikita Petrov (Positive Technologies).

Additional Resources / Links

Share:

BugZero® Risk Score

What's this?

Coming soon

Status

Solved

Learn More

Search:

...