HomeSecurityVeeam Backup: Critical RCE vulnerabilities allow remote code execution

Veeam Backup: Critical RCE vulnerabilities allow remote code execution

Veeam Software has disclosed three serious security vulnerabilities in its Backup & Replication and Agent for Microsoft Windows, which allow remote code execution and privilege escalation, potentially compromising enterprise backup infrastructures.

See also: Users locked out of Veeam Recovery Orchestrator

Veeam

These vulnerabilities, which were fixed in recent updates, primarily affect domain-joined systems on version 12 of the software. Organizations are urged to apply the fixes immediately to prevent potential data breaches or ransomware.

The first critical issue, CVE-2025-48983, is in the Mount of Veeam Backup & Replication, allowing an authenticated domain user to execute arbitrary code on the hosting backup infrastructure. With a CVSS v3.1 score of 9.9, this vulnerability was reported by CODE WHITE and affects all versions 12 through 12.3.2.3617, including older versions that are no longer supported and are potentially vulnerable.

The company notes that only domain-joined configurations are at risk, while Veeam Software Appliance and the upcoming version 13 remain architecturally unaffected. The patch, version 12.3.2.4165, resolves the issue by hardening the service against unauthorized code injection. Administrators are advised to follow Veeam best practices, preferring workgroup configurations over domain integration for increased security.

See also: Veeam warns of new serious vulnerability in VBR

Veeam Backup: Critical RCE vulnerabilities allow remote code execution

Equally serious is CVE-2025-48984, another RCE vulnerability targeting the Backup Server, exploitable by authenticated domain users with a perfect CVSS score of 9.9. It was discovered by Sina Kheirkhah and Piotr Bazydlo of watchTowr, and shares the same affected versions as CVE-2025-48983, limited to domain-joined Veeam Backup & Replication v12 environments. Unsupported versions should be considered vulnerable, although they have not been explicitly tested. The same patch, 12.3.2.4165, eliminates this risk, emphasizing the need for rapid updates in hybrid or Active Directory-integrated setups. This gap highlights the risks of excessive domain access to backup systems, potentially allowing lateral movement across networks.

Complementing the RCE issues, CVE-2025-48982 affects the Veeam Agent for Microsoft Windows, allowing local privilege escalation if an administrator restores a malicious file, with a high CVSS severity score of 7.3. It was reported anonymously through Trend Micro’s Zero Day initiative, and affects versions up to 6.3.2.1205, integrated with Backup & Replication or standalone. The exploit requires tricking a user into restoring, but could significantly elevate the attacker’s privileges. Fixed in version 6.3.2.1302, this patch is critical for protecting endpoints in Windows environments.

See also: Veeam RCE flaw allows servers to be compromised

Veeam Backup: Critical RCE vulnerabilities allow remote code execution

The company recommends verifying all agent instances and isolating backups to reduce social engineering risks. Organizations using affected versions should prioritize updates to protect against code execution threats.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS