securityaffairs.com 22 Sept 2026, 10:13 UTC

Public Exploit Lets Local Users Gain SYSTEM Access on Veeam Agent

Public Exploit Lets Local Users Gain SYSTEM Access on Veeam Agent
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

A public proof-of-concept exploit for CVE-2026-32996 was released on 14 September 2026, exposing a critical local privilege-escalation flaw in Veeam Agent for Microsoft Windows. The vulnerability affects version 13.0.1.2067 and all earlier version 13 builds. It allows a local, low-privileged user to obtain NT AUTHORITY\SYSTEM privileges, potentially giving them complete control of a shared Windows endpoint.

Arctic Wolf warned that the publication of technical details and exploit code increases the likelihood of attempts against affected deployments, but the report does not confirm active exploitation.

The flaw lies in the Veeam Endpoint Backup service’s handling of elevated client sessions through the local gRPC named pipe `\\.\pipe\Veeam\VAW\ServiceConnectionPipe`. The service associates an elevated administrator session with a client-controlled session UID without binding it to the requesting user or connection. Standard users can read valid elevated UIDs from `C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log` and reuse them to execute commands as SYSTEM. The public PoC demonstrates the issue by running `whoami` and saving the result to a file.

Veeam recommends upgrading Veeam Backup & Replication to version 13.0.2.29 or later, which updates the Agent to fixed build 13.0.3.1220. Organisations should prioritise shared workstations, servers, administrator workstations and systems with local-user access, then verify that both service and tray components have been updated. There is no official workaround; unpatched systems should have local and interactive access restricted and unnecessary local administrator or backup-operator privileges removed.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline