Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN764
_____________________________________________________________________


DATE                : 16/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Veeam Backup & Replication
                    versions prior to 11.0.24, 10.1.57, 9.0.120.
 
=====================================================================

https://www.veeam.com/kb4879
_____________________________________________________________________



Veeam Software Appliance/Veeam Infrastructure Appliance — Updater
Component Vulnerability

KB ID:          4879
Product:        Veeam Backup & Replication | 13
Published:      2026-07-14
Last Modified:  2026-07-14


Veeam Software Security Commitment
Veeam® is committed to ensuring its products protect customers from
potential risks. As part of that commitment, we operate a
Vulnerability Disclosure Program (VDP) for all Veeam products and
perform extensive internal code audits. When a vulnerability is
identified, our team promptly develops a patch to address and
mitigate the risk. In line with our dedication to transparency, we
publicly disclose the vulnerability and provide detailed mitigation
information. This approach ensures that all potentially affected
customers can quickly implement the necessary measures to safeguard
their systems. It’s important to note that once a vulnerability and
its associated patch are disclosed, attackers will likely attempt
to reverse-engineer the patch to exploit unpatched deployments of
Veeam software. This reality underscores the critical importance
of ensuring that all customers use the latest versions of our
software and install all updates and patches without delay.


Vulnerability Details

A vulnerability in the Veeam Updater component allows a local user
to elevate their privileges and gain root-level access to the
underlying operating system.


Severity: High
CVSS Score: 8.4
Source: Reported through HackerOne by skydesperados.

Impacted Components:

    Veeam Software Appliance (Linux-based Veeam Backup & Replication Server)
    Veeam Infrastructure Appliance

This vulnerability does not affect Windows-based Veeam Backup &
Replication backup servers, but may affect remote components that
utilize the Veeam Infrastructure Appliance.


Solution

This vulnerability is resolved starting in the Veeam Updater component
version 12.3.0.65.

    Automatic Update Deployment — For most users, no action is needed,
as the Veeam Updater component installs the fix automatically during
its automatic update check.

    Manual Update Deployment — If the Veeam Software Appliance or any
Veeam Infrastructure Appliance is unable to reach either
repository.veeam.com or a local mirror repository, the fix must be
applied manually with assistance from Veeam Support, or temporary
internet access to the update server must be configured.


For more information about Veeam Appliance Update configuration,
review the product user guide:
Veeam Backup & Replication User Guide: Updating Veeam Appliances


Deployment Verification

To verify that the Veeam Updater component has been updated, review
the component versions on the Veeam Software Appliance or Veeam
Infrastructure Appliance using its Host Management Console:

    Open the appliance's Host Management Console Web UI.

    In the left-side navigation list, select the Logs and Services
section under the Support heading.

    Within the Logs and Services view, select the Components tab.

    Review the list of installed components and their respective
versions (optionally use the filter).

    Verify that the Veeam Updater component version listed is
12.3.0.65 or higher.

Veeam Host Management Console showing Logs and Services on the
Components tab, filtered for "Updater", with Veeam Updater
listed as version 12.3.0.65.

If this KB article did not resolve your issue or you need further
assistance with Veeam software, please create a Veeam Support Case.

To submit feedback regarding this article, please click this link:
Send Article Feedback

To report a typo on this page, highlight the typo with your mouse
and press CTRL + Enter.



=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




