Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.veeam.com/kb4902 |
|
Wed, 07 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local User Write-Anything After Admin Installation in Veeam Agent for Windows |
Wed, 07 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it. | |
| Weaknesses | CWE-1386 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-10-07T13:09:57.619Z
Reserved: 2025-10-31T15:00:01.446Z
Link: CVE-2025-64391
Updated: 2026-10-07T13:09:52.016Z
Status : Awaiting Analysis
Published: 2026-10-07T09:17:03.467
Modified: 2026-10-07T13:58:29.527
Link: CVE-2025-64391
No data.
OpenCVE Enrichment
Updated: 2026-10-07T11:00:10Z