Vulnerability record · CVE-2020-10915 · published 22 April 2020
CVE-2020-10915: Veeam ONE Agent unauthenticated .NET deserialization RCE
Veeam · One
Veeam ONE Agent 9.5.4.4587 fails to validate user-supplied data in the HandshakeResult method, allowing deserialization of untrusted data. Because the flaw is reachable without authentication over the network, it exposes the service account to remote code execution.
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-10401.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a CVSS score of 9.8 and very high EPSS probability makes this a top remediation priority.
What it is
Veeam ONE Agent 9.5.4.4587 fails to validate user-supplied data in the HandshakeResult method, allowing deserialization of untrusted data. Because the flaw is reachable without authentication over the network, it exposes the service account to remote code execution.
Impact
An unauthenticated remote attacker can execute arbitrary code in the context of the Veeam ONE Agent service account, potentially leading to full control of the affected host and any resources that account can reach.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required, per the CVSS vector and description. Any host that can reach the Veeam ONE Agent service can attempt exploitation.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.86619, 99.7th percentile), indicating substantial observed exploitation likelihood. Public references include a Packet Storm exploit writeup and ZDI advisory, suggesting exploit details are publicly available.
What to do
- Apply the vendor fix referenced in Veeam KB3144 for Veeam ONE Agent 9.5.4.4587.
- Restrict network access to the Veeam ONE Agent service to trusted management hosts only.
- Run the Veeam ONE Agent service under a least-privilege account to limit post-exploitation impact.
- Monitor vendor advisories for updated builds and verify the installed agent version after patching.
Detection
- Monitor for unexpected child processes spawned by the Veeam ONE Agent service account.
- Inspect network traffic to the Veeam ONE Agent service for anomalous or malformed handshake payloads.
- Alert on suspicious .NET deserialization activity or unusual assembly loads in the agent process.
- Review service account activity for lateral movement or credential access following agent connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157529/Veeam-ONE-Agent-.NET-Deserialization.html | |
| https://www.veeam.com/kb3144 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-546/ | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/157529/Veeam-ONE-Agent-.NET-Deserialization.html | |
| https://www.veeam.com/kb3144 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-546/ | Third Party AdvisoryVDB Entry |
Track CVE-2020-10915 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-10915), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.