Critical Veeam Backup & Replication RCE vulnerability fixed, patch ASAP! (CVE-2025-23120)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-40711 | Unauthenticated Deserialization RCE in Veeam Backup & Replication Veeam Backup & Replication contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to send a maliciously crafted serialized payload to the product's network-facing service and achieve remote code execution, with no privileges or user interaction required (CVSS 3.1: 9.8). Successful exploitation yields full code execution on the backup server with high impact on confidentiality, integrity and availability, and is especially valuable to attackers because backup infrastructure typically stores credentials and ransomware operators seek to destroy or encrypt backups before attacking production systems. Any organization running Veeam Backup & Replication is in scope; the provided data does not specify exact affected version ranges, so consult Veeam's advisory for the affected/fixed builds. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-10-17 with known ransomware use, a public proof-of-concept has been published by watchTowr, EPSS estimates a 90.4% probability of exploitation within 30 days (100th percentile), and the exploit has been reused in Frag ransomware attacks. Do: Apply Veeam's security updates immediately (the vendor released fixes for 18 flaws, including 5 critical ones); per the KEV required action, apply mitigations per Veeam's instructions or discontinue use if mitigations are unavailable. Until patched, restrict network access to the backup server from untrusted networks and remove unnecessary internet exposure. Given confirmed ransomware exploitation, also hunt for signs of compromise on backup servers and review backup job integrity and stored credentials. | 9.8 | 90% | KEV ransomware PoC |
| mass≈ hundreds of thousands of on-prem backup server deployments plausibly affected (tens of thousands internet-exposed) | |
| CVE-2025-23120 | Domain-User RCE via Deserialization in Veeam Backup & Replication Veeam Backup & Replication contains a deserialization of untrusted data flaw (CWE-502) that allows remote code execution. Per the CVSS vector (AV:N/AC:L/PR:L/UI:N), the attack is network-reachable, straightforward to execute, and requires only low-privilege credentials — a regular domain user — with no user interaction; the vendor description states it yields RCE 'for domain users'. An attacker who obtains or already holds any domain-user account that can reach the backup server gains code execution with high confidentiality, integrity and availability impact, a foothold that is especially dangerous in backup infrastructure because those servers often hold credentials for large parts of the estate and are prime ransomware targets. Any organization running Veeam Backup & Replication is potentially affected. Veeam has released a fix (reported alongside its patch for the related CVE-2025-23121, rated 9.9, in the same product); a public technical write-up/PoC from watchTowr exists, the flaw is not yet in CISA's KEV, and EPSS assigns a 24% probability (98th percentile) of exploitation within 30 days. Do: Upgrade Veeam Backup & Replication to the patched release specified in Veeam's security advisory; if you already applied the fix for the related CVE-2025-23121 (CVSS 9.9), verify you are on the newest build, as this flaw was disclosed alongside that patch. Restrict network access to backup infrastructure, review which domain accounts can reach the B&R server, and monitor for exploitation attempts given the public PoC and elevated EPSS score. | 8.8 | 24% | PoC |
| large≈ hundreds of thousands of enterprise installations (Veeam's flagship product; Veeam has publicly reported 550,000+ customers) |
Full article333 words · extracted from helpnetsecurity.com · click to collapse
Veeam has released fixes for a critical remote code execution vulnerability (CVE-2025-23120) affecting its enterprise Veeam Backup & Replication solution, and is urging customers to quickly upgrade to a fixed version.

There is currently no indication that the vulnerability is being leveraged by attackers. It was privately reported by researcher Piotr Bazydlo of watchTowr Labs, who followed the release of the patch with a technical write-up and pointers on how a proof-of-concept exploit for a previously discovered vulnerability (CVE-2024-40711) can be modified to exploit CVE-2025-23120.
About CVE-2025-23120
CVE-2025-23120 – which actually covers two RCE vulnerabilities based on similar deserialization gadgets – affects Veeam Backup & Replication versions 12, 12.1, 12.2, and 12.3. “Unsupported product versions are not tested, but are likely affected and should be considered vulnerable,” the company says.
The semi-good news is that the vulnerability affects only Backup & Replication servers that are joined to the organization’s Active Directory domain, and can be exploited only by authenticated domain users.
“Veeam explicitly mentions that domain-joined backup servers are against security and compliance best practices, but in reality, we believe this is likely to be a relatively common configuration,” Rapid7 researchers noted.
They also pointed out that Veeam backup servers being accessed or exploited by attackers usually happens once an adversary has already established a foothold in the target environment.
“Imagine that any employee of your 50 000 people organization can get SYSTEM on your backup server. Kind of scary, right? Especially when you think about those threat actors that seemingly and magically appear to get shellz on your endpoints,” Bazydlo commented.
Keeping in mind that ransomware attackers usually go after backups, that Veeam Backup & Replication vulnerabilities are regularly exploited by them, and that clever attackers will know how to develop an exploit based on the available information, enterprise admins should move quickly.
“Customers should update to the latest version of the software (12.3 build 12.3.1.1139) immediately, without waiting for a regular patch cycle to occur,” Rapid7 researchers advised.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/03/20/critical-veeam-backup-replication-rce-vulnerability-cve-2025-23120/