CVE-2025-64391: Veeam Agent For Windows
Medium severity, CVSS 4.1. EPSS: 0.1% chance of exploitation in the next 30 days.
This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.
Affected products
- Veeam Agent For Windows: before 13.1 (fixed in 13.1)
Published 2026-10-07. Last modified 2026-10-07.