Impact
A flaw in Veeam ONE permits a user with elevated local privileges to execute arbitrary code on the server, allowing the attacker to compromise the integrity and confidentiality of the system. The vulnerability is an instance of Code Injection (CWE-94) and could be leveraged to gain full control over the affected platform.
Affected Systems
Veeam ONE is the only product identified as affected. No specific version information is provided, so any installation lacking the latest vendor fixes should be considered at risk.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation yet a potentially serious attack vector for authenticated users with high privileges. If an attacker can locally authenticate as a privileged user, the vulnerability could be readily exploited to execute malicious code.
OpenCVE Enrichment