Veeam has fixed a critical remote code execution (RCE) vulnerability , tracked as CVE-2025-23120 , in its Backup & Replication software , which affects domain-joined installations.
See also: Critical PHP RCE vulnerability used in new attacks

An RCE bug refers to a security vulnerability in a system or application that allows an attacker to execute code on a computer or server remotely. This can happen without the need for physical access to the computer or server, provided that the attacker has the ability to send malicious code over the network. This vulnerability can occur for a variety of reasons, such as poorly written or poorly protected code, data validation failures, or weak authentication mechanisms.
The RCE bug was recently discovered and affects Veeam Backup & Replication version 12.3.0.310 as well as all previous versions 12. The company fixed it in version 12.3.1 (build 12.3.1.1139) , which was released yesterday.
According to a technical report from watchTowr Labs, who discovered the bug, CVE-2025-23120 is a deserialization vulnerability in Veeam.Backup.EsxManager.xmlFrameworkDs and Veeam.Backup.Core.BackupSummary .NET.
See also: Voyager management package is vulnerable to RCE flaw
A deserialization vulnerability occurs when an application incorrectly processes serialized data, allowing attackers to insert malicious objects or “gadgets” that can execute malicious code.

Last year, while patching a previous data acceptance bug discovered by researcher Florian Hauser, Veeam introduced a blacklist of known gadgets that could exploit the bug.
However, watchTowr was able to find a different gadget chain that was not on Veeam's blacklist for achieving RCE.
The good news is that the bug only affects Veeam Backup & Replication installations that are joined to a domain. The bad news is that any user on the domain can exploit this vulnerability, making it easily exploitable in these setups. Unfortunately, many companies have joined their Veeam server to a Windows domain, ignoring established company best practices.
See also: New Docker 1-Click RCE attack exploits API misconfigurations
While there are no reports of this bug being exploited in the real world, watchTowr has shared several technical details, which makes it possible to release a proof-of-concept (PoC) soon.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
