CVE-2024-45207
Severity CVSS v4.0:
Pending analysis
Type:
CWE-426
Untrusted Search Path
Publication date:
04/12/2024
Last modified:
02/07/2025
Description
DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services
Impact
Base Score 3.x
7.00
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:veeam:veeam_agent_for_windows:*:*:*:*:*:*:*:* | 6.0.0.959 (including) | 6.3.0.177 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



