Comprehensive data protection for all workloads
Locked
lando_uk
Veteran
Posts: 389
Liked: 43 times
Joined: Oct 17, 2013 10:02 am
Full Name: Mark
Location: UK
Contact:

CVE-2025-48982 - Veeam Agent for Microsoft Windows - Privilege Escalation

Post by lando_uk »

I'm on version 12.3.2.4165 and its still scanning that the Veeam agent needs patching on the actual B&R server.
Patch Scanning - oval:org.secpod.oval:def:10017353 Definition: Veeam Agent is installed; Veeam Agent is less than 6.3.2.1302; Veeam's private fix is not installed. Specifics: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ABD64ABC-C05B-4B0A-9D58-1FEBC8A845C8}\DisplayVersion: value is 6.3.2.1205.
I have a couple of windows agents and they are on 6.3.2.1205 but they show Fixes Installed: 10765569.

So do i need to update the actual B&R server manually? Do i just run the hotfix in C:\Program Files\Veeam\Veeam Distribution Service\Fixes\vaw\kb.1076569\veeam_backup_6.3.2.1205_PrivateFix_TF1076569.exe or do I download the latest copy of the agent and just upgrade it that way?

thanks
Gostev
former Chief Product Officer (until 2026)
Posts: 33078
Liked: 8146 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: CVE-2025-48982 - Veeam Agent for Microsoft Windows - Privilege Escalation

Post by Gostev »

Hi, kindly always use search before creating new topics. It's extremely unlikely you can ever be the first to have some Veeam-related question, especially when talking about a 2 months old patch. Just past the CVE in the Search box and hit Enter, and you will see an existing discussion where all possible questions have already been answered back in October.

I'm locking this discussion as duplicate.
Locked

Who is online

Users browsing this forum: Amazon [Bot], Google [Bot] and 240 guests