Watch out, Veeam fixed a new critical bug in Backup & Replication product
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-23120 | Domain-User RCE via Deserialization in Veeam Backup & Replication Veeam Backup & Replication contains a deserialization of untrusted data flaw (CWE-502) that allows remote code execution. Per the CVSS vector (AV:N/AC:L/PR:L/UI:N), the attack is network-reachable, straightforward to execute, and requires only low-privilege credentials — a regular domain user — with no user interaction; the vendor description states it yields RCE 'for domain users'. An attacker who obtains or already holds any domain-user account that can reach the backup server gains code execution with high confidentiality, integrity and availability impact, a foothold that is especially dangerous in backup infrastructure because those servers often hold credentials for large parts of the estate and are prime ransomware targets. Any organization running Veeam Backup & Replication is potentially affected. Veeam has released a fix (reported alongside its patch for the related CVE-2025-23121, rated 9.9, in the same product); a public technical write-up/PoC from watchTowr exists, the flaw is not yet in CISA's KEV, and EPSS assigns a 24% probability (98th percentile) of exploitation within 30 days. Do: Upgrade Veeam Backup & Replication to the patched release specified in Veeam's security advisory; if you already applied the fix for the related CVE-2025-23121 (CVSS 9.9), verify you are on the newest build, as this flaw was disclosed alongside that patch. Restrict network access to backup infrastructure, review which domain accounts can reach the B&R server, and monitor for exploitation attempts given the public PoC and elevated EPSS score. | 8.8 | 24% | PoC |
| large≈ hundreds of thousands of enterprise installations (Veeam's flagship product; Veeam has publicly reported 550,000+ customers) | |
| CVE-2025-23121 +1 in the same advisory: …24286 | Authenticated Domain-User RCE in Veeam Backup & Replication CVE-2025-23121 is a code-injection vulnerability (CWE-94) in Veeam Backup & Replication that allows an authenticated domain user to execute arbitrary code on the Backup Server over the network. An attacker triggers it by sending a crafted request to the backup server's network-facing components using valid, low-privileged domain credentials, with no user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity and availability of the backup server (CVSS 3.1: 8.8 per the vector provided, though some coverage lists a 9.9 score). Any organization running Veeam Backup & Replication is affected, particularly environments where many or low-privilege domain accounts can reach the backup server. As of this writing it is not in CISA KEV and no public PoC is known, but the EPSS of 22.2% (98th percentile) indicates an elevated probability of exploitation within the next 30 days, and Veeam has shipped a fix. Do: Upgrade Veeam Backup & Replication to the latest patched release per Veeam's security advisory for CVE-2025-23121. In the meantime, restrict which domain accounts can authenticate to the Backup Server, ensure the server is not exposed to the public internet, and audit for unusual process execution or network connections from backup infrastructure. Given the high EPSS score, prioritize patching and monitor Veeam/Kev feeds for signs of in-the-wild exploitation. | 8.8 group max | 22% |
| mass≈ hundreds of thousands of backup-server deployments (order of 10^5–10^6 installations) | ||
| CVE-2025-24287 | A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions. A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions. NVD description · AI analysis pending | 6.1 | <1% | — | — |
Full article354 words · extracted from securityaffairs.com · click to collapse

Veeam addressed a new critical flaw in Backup & Replication product that could potentially result in remote code execution.
Veeam has rolled out security patches to address a critical security vulnerability, tracked CVE-2025-23121 (CVSS score of 9.9) in its Backup & Replication solution that can allow remote attackers to execute arbitrary code under certain conditions.
“A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.” reads the advisory published by the vendor.
The vulnerability impacts Backup & Replication 12.3.1.1139 and all earlier version 12 builds.
Researchers at CODE WHITE GmbH and watchTowr have reported the vulnerability to the company.
Rapid7 researchers, in a technical analysis of the bug, reported that after the patch for CVE-2025-23120 was released in March 2025, researchers revealed it could be bypassed leading to CVE-2025-23121. Veeam’s June 17 advisory rates it 9.9 CVSS and confirms that authenticated domain users can exploit it, mirroring the conditions of the earlier CVE.
“CVE-2025-23121 is credited to security researchers at CODE WHITE GmbH and watchTowr. In March 2025, following the release of the patch for Veeam Backup & Replication’s CVE-2025-23120, these researchers publicly stated that the patch for CVE-2025-23120 could be bypassed.” reported Rapid7. “Veeam’s June 17 advisory states that CVE-2025-23121 is authenticated, the CVSS score is 9.9, and “authenticated domain users” can exploit the vulnerability; all of these details align with the advisory for CVE-2025-23120.”
Veeam also addressed another issue, tracked as CVE-2025-24286, CVSS score: 7.2), impacting the Backup & Replication product.
An authenticated user with the Backup Operator role could exploit the issue to modify backup jobs, which could execute arbitrary code. Nikolai Skliarenko with Trend Micro discovered the vulnerability.
The third issue addressed by the company, tracked as CVE-2025-24287, CVSS score: 6.1), affected Veeam Agent for Microsoft Windows.
“A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.” states the advisory.
CrisprXiang disclosed the flaw through Trend Micro Zero Day Initiative.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Backup & Replication)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/179109/security/watch-out-veeam-fixed-a-new-critical-bug-in-backup-replication-product.html