CVE-2025-64391: Medium severity Veeam Veeam Agent for Microsoft Windows vulnerability
This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running Veeam Agent for Microsoft Windows are exposed when a low-privileged local user can act on the machine and an administrator installs the agent.
What does an attacker need to exploit it?
The attacker needs low-privileged local access and user interaction in the form of an administrator installing the agent. The issue is locally exploitable, not described as remotely exploitable.
What is the security impact?
A low-privileged local user can cause the agent to write files to arbitrary locations during administrator-led installation. The supplied CVSS vector indicates high impact to integrity, with no stated confidentiality or availability impact.