ZeroHour

CVE-2025-23120

PoC large

Domain-User RCE via Deserialization in Veeam Backup & Replication

CVSS 3.1
8.8 high
EPSS
24%p98
Published
()
Modified
AI analysis

Veeam Backup & Replication contains a deserialization of untrusted data flaw (CWE-502) that allows remote code execution. Per the CVSS vector (AV:N/AC:L/PR:L/UI:N), the attack is network-reachable, straightforward to execute, and requires only low-privilege credentials — a regular domain user — with no user interaction; the vendor description states it yields RCE 'for domain users'. An attacker who obtains or already holds any domain-user account that can reach the backup server gains code execution with high confidentiality, integrity and availability impact, a foothold that is especially dangerous in backup infrastructure because those servers often hold credentials for large parts of the estate and are prime ransomware targets. Any organization running Veeam Backup & Replication is potentially affected. Veeam has released a fix (reported alongside its patch for the related CVE-2025-23121, rated 9.9, in the same product); a public technical write-up/PoC from watchTowr exists, the flaw is not yet in CISA's KEV, and EPSS assigns a 24% probability (98th percentile) of exploitation within 30 days.

What to do: Upgrade Veeam Backup & Replication to the patched release specified in Veeam's security advisory; if you already applied the fix for the related CVE-2025-23121 (CVSS 9.9), verify you are on the newest build, as this flaw was disclosed alongside that patch. Restrict network access to backup infrastructure, review which domain accounts can reach the B&R server, and monitor for exploitation attempts given the public PoC and elevated EPSS score.

Affected
Veeam Backup & Replication
Estimated exposure
large≈ hundreds of thousands of enterprise installations (Veeam's flagship product; Veeam has publicly reported 550,000+ customers) — Veeam Backup & Replication is one of the most widely deployed enterprise backup products with a customer base in the hundreds of thousands, though this flaw additionally requires a (compromised or malicious) domain-user account with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability allowing remote code execution (RCE) for domain users.

Vendors
veeam
Products
veeam backup \& replication
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news