https://reddit.com/r/netsec/comments/1jff8u9/by_executive_order_we_are_banning_blacklists/: By Executive Order, We Are Banning Blacklists - Domain-Level RCE in Veeam Backup & Replication (CVE-2025-23120) - watchTowr Labs
Published Mar 20, 2025
·Updated
Affected Software
1 affected component
Veeam Backup & Replication
Frequently Asked Questions
1
What is the severity of CVE-2025-23120?
CVE-2025-23120 is rated as critical due to the potential for remote code execution.
2
How do I fix CVE-2025-23120?
To fix CVE-2025-23120, update Veeam Backup & Replication to the latest version provided by the vendor.
3
What systems are affected by CVE-2025-23120?
CVE-2025-23120 affects all versions of Veeam Backup & Replication prior to the security update.
4
What kind of vulnerability is CVE-2025-23120?
CVE-2025-23120 is classified as a remote code execution vulnerability, allowing an attacker to run arbitrary code.
5
Who should be concerned about CVE-2025-23120?
Organizations using Veeam Backup & Replication should prioritize addressing CVE-2025-23120 to prevent exploitation.