Impact
A vulnerability exists in the Veeam Updater component of the Veeam Software Appliance that allows an authenticated local user to elevate privileges and gain root-level access to the underlying operating system. This flaw, categorized as CWE‑22, enables an attacker who can execute code locally to bypass normal permission boundaries. The resulting root access would give full control over the appliance, potentially exposing backup data, enabling further lateral movement, and compromising overall infrastructure security.
Affected Systems
All installations of Veeam Backup and Replication that include the Updater component may be impacted; no specific version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access, meaning an attacker must already have some form of local presence or physical access to the appliance to launch the attack.
OpenCVE Enrichment