Executive brief
A vulnerability in Veeam Backup & Replication allows a user with low-level access to a Windows server to gain full administrative control. Veeam is a critical data protection and backup solution used to safeguard corporate data; an attacker who gains administrative rights could potentially access, modify, or delete sensitive backups. This could lead to significant data loss or provide a foothold for further attacks within the corporate network.
Technical details
A local privilege escalation vulnerability exists in Windows-based Veeam Backup & Replication servers. The flaw is categorized as CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory), suggesting that sensitive data or configuration files may be improperly secured, allowing a low-privileged local user to leverage this information to escalate their privileges. An attacker with local access and low-level permissions can achieve full system or administrative control (Scope: Changed). The vulnerability is resolved in Veeam Backup & Replication versions 12.3.2.4465 and 13.0.1.2067.
Affected products
- Veeam Backup & Replication 12, 12.1, 12.2, 12.3, 12.3.1, 12.3.2 (prior to build 12.3.2.4465)
- Veeam Backup & Replication 13 (prior to build 13.0.1.2067)
Timeline
- 2026-03-12: disclosed: Initial disclosure via NVD and Veeam KB articles.
- 2026-03-12: patched: Fixed in builds 12.3.2.4465 and 13.0.1.2067.
- 2026-04-16: other: Veeam KB articles last modified.