Impact
A local low‑privileged user can capture the NTLM credentials of the Reporter service account. With those credentials the attacker can impersonate the service account, potentially escalating privileges or accessing protected resources. The weakness corresponds to Information Exposure (CWE‑522).
Affected Systems
The vulnerability affects Veeam ONE, with no specific version information provided. All current releases of Veeam ONE are potentially vulnerable until patches are applied.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, but the high CVSS suggests a serious risk. The weakness is exploitable by a local user with standard privileges; there is no indication of a remote attack vector. Consequently, attackers need local access but can use the captured credentials to impersonate the Reporter service account.
OpenCVE Enrichment