Veeam · Veeam One Agent · CVE-2020-10914
**Name of the Vulnerable Software and Affected Versions**
VEEAM One Agent version 9.5.4.4587
**Description**
This issue allows remote attackers to execute arbitrary code on affected installations. Authentication is not required to exploit this issue. The flaw exists within the `PerformHandshake` method and results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this issue to execute code in the context of the service account.
**Recommendations**
For VEEAM One Agent version 9.5.4.4587, as a temporary workaround, consider restricting access to the `PerformHandshake` method until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.