PT-2026-107228 · Veeam · Veeam Backup & Replication
CVE-2025-64393
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Veeam Backup & Replication versions prior to 12.3.2 P4
Description
A deserialization issue allows a user with Backup Viewer privileges to execute arbitrary code as SYSTEM on the backup server. Deserialization is the process of converting a data stream back into an object, which can be exploited if the input is not properly validated.
Recommendations
Update to version 12.3.2 P4.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veeam Backup & Replication