← Vulnerability feed

Vulnerability record · CVE-2020-10915 · published 22 April 2020

CVE-2020-10915: Veeam ONE Agent unauthenticated .NET deserialization RCE

Veeam · One

Veeam ONE Agent 9.5.4.4587 fails to validate user-supplied data in the HandshakeResult method, allowing deserialization of untrusted data. Because the flaw is reachable without authentication over the network, it exposes the service account to remote code execution.

9.8 CVSS 3.1 Critical EPSS 87% · top 0.3% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-10401.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a CVSS score of 9.8 and very high EPSS probability makes this a top remediation priority.

What it is

Veeam ONE Agent 9.5.4.4587 fails to validate user-supplied data in the HandshakeResult method, allowing deserialization of untrusted data. Because the flaw is reachable without authentication over the network, it exposes the service account to remote code execution.

Impact

An unauthenticated remote attacker can execute arbitrary code in the context of the Veeam ONE Agent service account, potentially leading to full control of the affected host and any resources that account can reach.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required, per the CVSS vector and description. Any host that can reach the Veeam ONE Agent service can attempt exploitation.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.86619, 99.7th percentile), indicating substantial observed exploitation likelihood. Public references include a Packet Storm exploit writeup and ZDI advisory, suggesting exploit details are publicly available.

What to do

  • Apply the vendor fix referenced in Veeam KB3144 for Veeam ONE Agent 9.5.4.4587.
  • Restrict network access to the Veeam ONE Agent service to trusted management hosts only.
  • Run the Veeam ONE Agent service under a least-privilege account to limit post-exploitation impact.
  • Monitor vendor advisories for updated builds and verify the installed agent version after patching.

Detection

  • Monitor for unexpected child processes spawned by the Veeam ONE Agent service account.
  • Inspect network traffic to the Veeam ONE Agent service for anomalous or malformed handshake payloads.
  • Alert on suspicious .NET deserialization activity or unusual assembly loads in the agent process.
  • Review service account activity for lateral movement or credential access following agent connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-10915 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38547Veeam one information exposure vulnerabilityA vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configur…EPSS 19%9.8CVE-2020-10914Veeam ONE Agent unauthenticated .NET deserialization RCEVeeam ONE Agent 9.5.4.4587 fails to validate user-supplied data in the PerformHandshake method, allowing deserialization of untrusted data. Because t…EPSS 48%analysed8.8CVE-2024-42023Veeam one improper access control vulnerabilityAn improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.EPSS 0.47%8.8CVE-2024-42024Veeam one execution with unnecessary privileges vulnerabilityA vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the mach…EPSS 1.3%8.0CVE-2024-42019Veeam one information exposure vulnerabilityA vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction …EPSS 0.54%6.5CVE-2024-42021Veeam one improper access control vulnerabilityAn improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.EPSS 0.30%5.4CVE-2024-42020Veeam one cross-site scripting vulnerabilityA Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.EPSS 0.41%5.4CVE-2023-38549Veeam one cross-site scripting vulnerabilityA vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the accou…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2020-10915), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.