CVE-2025-48982

7.3

Veeam · Agent for Microsoft Windows

A local privilege escalation vulnerability in Veeam Agent for Microsoft Windows allows attackers to elevate privileges by tricking administrators into restoring a malicious file.

Executive summary

A local privilege escalation vulnerability in Veeam Agent for Microsoft Windows poses a significant security risk, as it allows attackers to gain elevated system access through social engineering.

Vulnerability

This vulnerability involves a flaw in the file restoration process, enabling an attacker to achieve local privilege escalation by manipulating an administrator into restoring a malicious file. Successful exploitation requires local access and user interaction.

Business impact

The ability to escalate privileges locally presents a severe risk to organizational security, potentially allowing an attacker to bypass standard access controls and gain administrative control over the host system. With a CVSS score of 7.3, this high-severity vulnerability could lead to complete system compromise, unauthorized data access, and the potential for lateral movement within the network.

Remediation

Immediate Action: Update Veeam Agent for Microsoft Windows to the latest version provided by the vendor in KB4771 to patch the vulnerability.

Proactive Monitoring: Monitor system logs for unusual file restoration activities or unexpected administrative privilege changes on systems running the Veeam agent.

Compensating Controls: Enforce strict least privilege policies for administrative accounts and educate personnel on the risks associated with restoring files from untrusted or unverified sources.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for total system compromise through local privilege escalation, organizations should prioritize updating the Veeam Agent for Microsoft Windows immediately. Security teams must ensure that administrative workflows involving file restoration are conducted in accordance with secure practices to mitigate the risk of exploitation.

More Veeam CVEs

Sources