CVE-2020-10915: Veeam ONE HandshakeResult Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-10401.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Veeam ONE. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Veeam ONE vulnerability?
The vulnerability ID for this Veeam ONE vulnerability is CVE-2020-10915.
What is the severity of CVE-2020-10915?
CVE-2020-10915 has a severity rating of 9.8 (Critical).
What does the CVE-2020-10915 vulnerability allow?
The CVE-2020-10915 vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.
Is authentication required to exploit CVE-2020-10915?
No, authentication is not required to exploit CVE-2020-10915.
How can I fix the CVE-2020-10915 vulnerability?
To fix the CVE-2020-10915 vulnerability, ensure that you have installed the latest security updates from Veeam and follow the recommended mitigation steps provided by the vendor.