A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges. The vulnerability exists because remote calls bypass permission checks, leading to full system compromise.
| Software | From | Fixed in |
|---|---|---|
| veeam / veeam_backup_&_replication | 12.0.0.1402 | 12.3.0.310 |