CVE-2025-23120: Critical severity veeam backup & replication vulnerability
Published Mar 20, 2025
·Updated
A vulnerability allowing remote code execution (RCE) for domain users.
Affected Software
1 affected component
Veeam Veeam Backup \& Replication>=12.0.0.1402<12.3.1.1139
Event History
Mar 20, 2025
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionSeverity
News Published
via The Register·06:33 PM
News Published
via The Register·06:37 PM
News Published
via BleepingComputer·11:30 PM
News Published
via BleepingComputer·11:32 PM
Jun 17, 2025
News Published
via BleepingComputer·03:42 PM
Jun 18, 2025
News Published
via The Register·01:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-23120?
CVE-2025-23120 has been classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-23120?
To mitigate CVE-2025-23120, it is essential to update Veeam Backup & Replication to the latest version beyond 12.3.1.1139.
3
Who is affected by CVE-2025-23120?
CVE-2025-23120 affects domain users who utilize vulnerable versions of Veeam Backup & Replication.
4
What impact does CVE-2025-23120 have on systems?
The impact of CVE-2025-23120 enables attackers to execute arbitrary code remotely, compromising system integrity.
5
Is there a workaround for CVE-2025-23120?
Currently, the best practice for CVE-2025-23120 is to apply the available patches rather than relying on a workaround.