7.8

CVE-2022-26503

Warnung
Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VeeamVeeam Version >= 4.0.0 < 4.0.2.2208
   MicrosoftWindows Version-
VeeamVeeam Version >= 5.0.0 < 5.0.3.4708
   MicrosoftWindows Version-
VeeamVeeam Version2.0
   MicrosoftWindows Version-
VeeamVeeam Version2.1
   MicrosoftWindows Version-
VeeamVeeam Version2.2
   MicrosoftWindows Version-
VeeamVeeam Version3.0.2
   MicrosoftWindows Version-
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.07% 0.882
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.