VYPR
High severity7.8NVD Advisory· Published Mar 17, 2022· Updated Jun 17, 2026

CVE-2022-26503

CVE-2022-26503

Description

Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Veeam/Veeam5 versions
    cpe:2.3:a:veeam:veeam:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:veeam:veeam:*:*:*:*:*:*:*:*range: >=4.0.0,<4.0.2.2208
    • cpe:2.3:a:veeam:veeam:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:veeam:veeam:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:veeam:veeam:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:veeam:veeam:3.0.2:*:*:*:*:*:*:*
  • Veeam/Agent For Windowscpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.