CVE-2022-26503 is a critical deserialization of untrusted data vulnerability affecting Veeam Agent for Windows versions 2.0 through 5.x. This flaw allows a local attacker to execute arbitrary code with SYSTEM privileges, posing a significant risk to affected systems. With a CVSS score of 7.8 (High), it has a low attack complexity and requires local user privileges, leading to high impacts on confidentiality, integrity, and availability. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered notable community discussion and media coverage, including reports of CISA warnings regarding exploited Veeam vulnerabilities, though not specifically confirming exploitation of this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.0.2.2208CPE matchmatch criteria | cpe:2.3:a:veeam:veeam:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.0.3.4708CPE matchmatch criteria | cpe:2.3:a:veeam:veeam:*:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:veeam:veeam:2.0:*:*:*:*:*:*:* | ||
2.1CPE matchmatch criteria | cpe:2.3:a:veeam:veeam:2.1:*:*:*:*:*:*:* | ||
2.2CPE matchmatch criteria | cpe:2.3:a:veeam:veeam:2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.