This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.veeam.com/kb4902 |
|
History
Wed, 07 Oct 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local User Write-Anything After Admin Installation in Veeam Agent for Windows |
Wed, 07 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it. | |
| Weaknesses | CWE-1386 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-10-07T08:49:13.273Z
Reserved: 2025-10-31T15:00:01.446Z
Link: CVE-2025-64391
No data.
Status : Received
Published: 2026-10-07T09:17:03.467
Modified: 2026-10-07T09:17:03.467
Link: CVE-2025-64391
No data.
OpenCVE Enrichment
Updated: 2026-10-07T11:00:10Z
Weaknesses