High8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

PT-2022-08: Deserialization of untrusted data in Veeam Agent for Microsoft Windows

Error type:

  • CWE-502:Deserialization of Untrusted Data

Vulnerability vector:

  • Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Severity (CVSSv3.1): 7.8 (high)
  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • Severity (CVSSv4.0): 8.5 (high)

Description:

The vulnerability was identified in Veeam Agent for Windows versions 2.0, 2.1, 2.2, 3.0.2, 4.0, and 5.0.

The discovered vulnerability allows local users to run arbitrary code with LOCAL SYSTEM privileges.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 12.03.2022

Recommendations:

Additional information: Security Bulletin

Researcher: Nikita Petrov (Positive Technologies)

Identifiers:

CVE-2022-26503

BDU:2022-01269

Vendor:

Veeam Software

Vulnerable product:

Veeam Agent for Windows

Vulnerable versions:

2.0, 2.1, 2.2, 3.0.2, 4.0, and 5.0