BlackTree Security · Infrastructure · Automation · AI

Public Exploit Code Can Turn a Local Veeam User Into SYSTEM

Public proof-of-concept code can now take a command supplied by a local user and execute it as NT AUTHORITY\SYSTEM through a vulnerable Veeam Agent for Microsoft Windows installation.

CVE-2026-32996 is a local privilege-escalation flaw. It is not a remote, unauthenticated route into a Windows machine, and public exploit code is not proof that attackers are using it in real incidents. It does change the risk of an existing foothold.

Backup software sits close to the assets attackers want

An attacker who has only a restricted local account may be unable to disable security controls, read protected data or tamper with recovery. SYSTEM rights remove many of those limits. On a backup endpoint, that can place credentials, restore operations and recovery evidence within reach.

The public repository demonstrates command execution and lists Veeam Agent 13.0.2.1102 and earlier as vulnerable. It identifies 13.0.3.1220 as fixed. Veeam’s own security-fix catalogue confirms that build 13.0.3.1220 contains the fix, while newer 13.0.4 and 13.1 releases are also available.

Do not reduce the check to a marketing version

  • Inventory the exact Veeam Agent build on every protected Windows endpoint.
  • Upgrade vulnerable version 13 deployments to a fixed, supported build.
  • Confirm the upgrade actually reached laptops and intermittently connected servers.
  • Review local accounts, interactive logons and process creation on systems that remained exposed after public code appeared.
  • Hunt for unexpected commands launched by Veeam services and for suspicious access to Veeam log files used during exploitation.
  • Protect backup credentials and recovery infrastructure as a separate trust tier.

Organisations still running the version 6 branch should use Veeam’s branch-specific support information rather than assuming the version 13 build numbers apply. Product inventory needs edition, branch and build, not simply the word Veeam.

The publication of an exploit narrows the gap between a low-privilege foothold and full machine control. It does not establish active exploitation of CVE-2026-32996. That distinction should shape the headline, but not delay the upgrade.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *