Skip to finding
important · Privilege escalation

New exploitation reports turn Veeam Agent's readable elevated-session identifier into a standard-user-to-SYSTEM path.

Affects

Veeam Agent for Microsoft Windows, endpoint-backup software installed on Windows workstations and servers.

A local standard user can read an elevated session UID from the Veeam service log, reuse it through the gRPC named pipe and submit a command executed as SYSTEM because the UID is not bound to its original user or connection. A fixed build exists, but affected end-of-life systems remain in scope.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 22, 2026