Description
This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.veeam.com/kb4902 |
|
History
Wed, 07 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it. | |
| Weaknesses | CWE-1386 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-10-07T08:49:13.273Z
Reserved: 2025-10-31T15:00:01.446Z
Link: CVE-2025-64391
No data.
Status : Received
Published: 2026-10-07T09:17:03.467
Modified: 2026-10-07T09:17:03.467
Link: CVE-2025-64391
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-1386
Insecure Operation on Windows Junction / Mount Point