---
id: CVE-2025-64391
title: >-
  This vulnerability in Veeam Agent for Microsoft Windows allows a
  low-privileged local user to make the agent write files to arbitrary locations
  when an administrator installs it.
summary: >-
  This vulnerability in Veeam Agent for Microsoft Windows allows a
  low-privileged local user to make the agent write files to arbitrary locations
  when an administrator installs it.
severity: medium
cvss: 4.1
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-1386
vendor: Veeam
product: Agent for Windows
affected:
  - agent_for_windows < 13.1
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T09:17:03.467'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64391'
references:
  - url: 'https://www.veeam.com/kb4902'
    label: support@hackerone.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-07T09:22:30.523Z'
---

## Overview

This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
