---
id: CVE-2025-48982
title: >-
  This vulnerability in Veeam Agent for Microsoft Windows allows for Local
  Privilege Escalation if a system administrator is tricked into restoring a
  malicious file.
summary: >-
  This vulnerability in Veeam Agent for Microsoft Windows allows for Local
  Privilege Escalation if a system administrator is tricked into restoring a
  malicious file.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: veeam
product: veeam_agent_for_windows
affected:
  - 'veeam_agent_for_windows >= 6.0.0.959, < 6.3.2.1302'
patched:
  - veeam_agent_for_windows 6.3.2.1302
published: '2025-10-31'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48982'
references:
  - url: 'https://www.veeam.com/kb4771'
    label: support@hackerone.com
tags:
  - nvd
epss: 0.00177
epssPercentile: 0.06694
ingestedAt: '2026-10-07T21:54:14.909Z'
---

## Overview

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.

## Affected

- `veeam_agent_for_windows >= 6.0.0.959, < 6.3.2.1302`

## Remediation

Upgrade past the affected range:

- `veeam_agent_for_windows 6.3.2.1302`
