CVE-2024-45207

HIGH

Veeam Agent for Windows - Code Injection

Title source: llm
STIX 2.1

Description

DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services

Scores

CVSS v3 7.0
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426
Status published
Products (1)
veeam/veeam_agent_for_windows 6.0.0.959 - 6.3.0.177
Published Dec 04, 2024
Tracked Since Feb 18, 2026