ZeroHour

CVE-2025-23121

mass

Authenticated Domain-User RCE in Veeam Backup & Replication

CVSS 3.1
8.8 high
EPSS
22%p98
Published
()
Modified
AI analysis

CVE-2025-23121 is a code-injection vulnerability (CWE-94) in Veeam Backup & Replication that allows an authenticated domain user to execute arbitrary code on the Backup Server over the network. An attacker triggers it by sending a crafted request to the backup server's network-facing components using valid, low-privileged domain credentials, with no user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity and availability of the backup server (CVSS 3.1: 8.8 per the vector provided, though some coverage lists a 9.9 score). Any organization running Veeam Backup & Replication is affected, particularly environments where many or low-privilege domain accounts can reach the backup server. As of this writing it is not in CISA KEV and no public PoC is known, but the EPSS of 22.2% (98th percentile) indicates an elevated probability of exploitation within the next 30 days, and Veeam has shipped a fix.

What to do: Upgrade Veeam Backup & Replication to the latest patched release per Veeam's security advisory for CVE-2025-23121. In the meantime, restrict which domain accounts can authenticate to the Backup Server, ensure the server is not exposed to the public internet, and audit for unusual process execution or network connections from backup infrastructure. Given the high EPSS score, prioritize patching and monitor Veeam/Kev feeds for signs of in-the-wild exploitation.

Affected
Veeam Backup & Replication (Backup Server component)
Estimated exposure
mass≈ hundreds of thousands of backup-server deployments (order of 10^5–10^6 installations) — Veeam Backup & Replication is the dominant enterprise backup product with a claimed 550,000+ customers, implying at least hundreds of thousands of deployed backup servers, though the flaw requires an authenticated domain user rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

Vendors
veeam
Products
veeam backup \& replication
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news