HomeSecurityVeeam RCE flaw allows servers to be compromised

Veeam RCE flaw allows servers to be compromised

Veeam has fixed a critical remote code execution (RCE) vulnerability , tracked as CVE-2025-23120 , in its Backup & Replication software , which affects domain-joined installations.

See also: Critical PHP RCE vulnerability used in new attacks

Veeam RCE

An RCE bug refers to a security vulnerability in a system or application that allows an attacker to execute code on a computer or server remotely. This can happen without the need for physical access to the computer or server, provided that the attacker has the ability to send malicious code over the network. This vulnerability can occur for a variety of reasons, such as poorly written or poorly protected code, data validation failures, or weak authentication mechanisms.

The RCE bug was recently discovered and affects Veeam Backup & Replication version 12.3.0.310 as well as all previous versions 12. The company fixed it in version 12.3.1 (build 12.3.1.1139) , which was released yesterday.

According to a technical report from watchTowr Labs, who discovered the bug, CVE-2025-23120 is a deserialization vulnerability in Veeam.Backup.EsxManager.xmlFrameworkDs and Veeam.Backup.Core.BackupSummary .NET.

See also: Voyager management package is vulnerable to RCE flaw

A deserialization vulnerability occurs when an application incorrectly processes serialized data, allowing attackers to insert malicious objects or “gadgets” that can execute malicious code.

Veeam RCE flaw allows servers to be compromised

Last year, while patching a previous data acceptance bug discovered by researcher Florian Hauser, Veeam introduced a blacklist of known gadgets that could exploit the bug.

However, watchTowr was able to find a different gadget chain that was not on Veeam's blacklist for achieving RCE.

The good news is that the bug only affects Veeam Backup & Replication installations that are joined to a domain. The bad news is that any user on the domain can exploit this vulnerability, making it easily exploitable in these setups. Unfortunately, many companies have joined their Veeam server to a Windows domain, ignoring established company best practices.

See also: New Docker 1-Click RCE attack exploits API misconfigurations

While there are no reports of this bug being exploited in the real world, watchTowr has shared several technical details, which makes it possible to release a proof-of-concept (PoC) soon.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS