Vulnerability record · CVE-2020-10914 · published 22 April 2020
CVE-2020-10914: Veeam ONE Agent unauthenticated .NET deserialization RCE
Veeam · One
Veeam ONE Agent 9.5.4.4587 fails to validate user-supplied data in the PerformHandshake method, allowing deserialization of untrusted data. Because the flaw is reachable without authentication over the network, it exposes the service to remote code execution.
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the PerformHandshake method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-10400.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable deserialization leading to code execution as a service account, with a CVSS of 9.8 and very high EPSS.
What it is
Veeam ONE Agent 9.5.4.4587 fails to validate user-supplied data in the PerformHandshake method, allowing deserialization of untrusted data. Because the flaw is reachable without authentication over the network, it exposes the service to remote code execution.
Impact
An attacker can execute arbitrary code in the context of the Veeam ONE Agent service account, which typically carries broad privileges over the monitored environment.
Attack surface
Reached over the network via the agent's handshake interface; the CVSS vector (AV:N/PR:N/UI:N) and description confirm no authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at roughly 0.479 (98.8th percentile), and public technical write-ups exist via Packet Storm and ZDI.
What to do
- Apply the vendor fix referenced in Veeam KB3144 for Veeam ONE Agent 9.5.4.4587.
- Restrict network access to the Veeam ONE Agent handshake port to trusted management hosts only.
- Run the agent service under a least-privilege account rather than a highly privileged service account.
- Monitor for and block unexpected inbound connections to agent endpoints from untrusted segments.
Detection
- Alert on Veeam ONE Agent service crashes or restarts that may indicate malformed deserialization payloads.
- Monitor for child processes spawned by the Veeam ONE Agent service, especially shells or scripting hosts.
- Inspect network traffic to agent handshake ports for anomalous or oversized serialized payloads.
- Review agent service account activity for unexpected command execution or lateral movement.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157529/Veeam-ONE-Agent-.NET-Deserialization.html | |
| https://www.veeam.com/kb3144 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-545/ | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/157529/Veeam-ONE-Agent-.NET-Deserialization.html | |
| https://www.veeam.com/kb3144 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-545/ | Third Party AdvisoryVDB Entry |
Track CVE-2020-10914 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-10914), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.