PT-2026-107228 · Veeam · Veeam Backup & Replication

CVE-2025-64393

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Veeam Backup & Replication versions prior to 12.3.2 P4
Description A deserialization issue allows a user with Backup Viewer privileges to execute arbitrary code as SYSTEM on the backup server. Deserialization is the process of converting a data stream back into an object, which can be exploited if the input is not properly validated.
Recommendations Update to version 12.3.2 P4.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64393

Affected Products

Veeam Backup & Replication