Impact
A flaw in Veeam ONE permits an attacker with local access to gain the privileges of the Reporter service, allowing the execution of arbitrary code or actions with privileges beyond those of the initiating user. This vulnerability is identified as CWE-269, which indicates a weakness in access control that can be exploited to elevate privileges. The impact is a loss of confidentiality, integrity, and availability for the affected system, as the attacker can manipulate the service and potentially other components running under the same credentials.
Affected Systems
Veeam ONE software is affected. No specific version range is provided in the vendor information, so the vulnerability could apply to any currently installed instance of Veeam ONE unless a patch has been applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4, indicating high severity. The EPSS score is not available, so the current exploitation probability is unknown; however, the lack of KEV listing suggests no widespread exploitation has been observed yet. It is inferred that the attack vector is local, as the description mentions a local privilege escalation. Exploitation would require an attacker to already have some level of local access or be able to bring a malicious payload to the target system.
OpenCVE Enrichment