CVE-2025-64391: Veeam Agent For Windows

Medium severity, CVSS 4.1. EPSS: 0.1% chance of exploitation in the next 30 days.

This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.

Affected products

  • Veeam Agent For Windows: before 13.1 (fixed in 13.1)

Published 2026-10-07. Last modified 2026-10-07.