PT-2025-25742 · Veeam · Veeam B&R+1

·

CVE-2025-23121

·

Published

2025-06-17

·

Updated

2026-08-24

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veeam Backup & Replication versions 12 through 12.3.2.3600
Description A flaw in the input validation mechanism allows an authenticated domain user to achieve remote code execution (RCE) on the backup server. This issue specifically impacts backup servers that are joined to a Windows domain, enabling any user with valid domain credentials to execute arbitrary code. Real-world incidents involving RCE in this software have been targeted by ransomware groups such as Frag, Akira, Fog, Cuba, and FIN7.
Recommendations Update to version 12.3.2.3617.

Fix

LPE

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06894
CVE-2025-23121

Affected Products

Veeam B&R
Veeam Backup & Replication