Veeam has released security updates today to fix several Veeam Backup & Replication (VBR) flaws, including a critical remote code execution (RCE) vulnerability. Tracked as CVE-2025-23121, this security flaw was reported by security researchers at watchTowr and CodeWhite, and it only impacts domain-joined installations. As Veeam explained in a Tuesday security advisory, the vulnerability can be exploited by authenticated domain users in low-complexity attacks to gain code execution remotely on the Backup Server. This flaw affects Veeam Backup & Replication 12 or later, and it was fixed in version 12.3.2.3617, which was released earlier today. While CVE-2025-23121 only impacts VBR installations joined to a domain, any domain user can exploit it, making it easy to abuse in those configurations. Unfortunately, many companies have joined their backup servers to a Windows domain, ignoring Veeam's best practices, which advise admins to use a separate Active Directory Forest and protect the administrative accounts with two-factor authentication. In March, Veeam patched another RCE vulnerability (CVE-2025-23120) in Veeam's Backup & Replication software that impacts domain-joined installations. Ransomware gangs have also told BleepingComputer years ago that they always target VBR servers because they simplify stealing victims' data and block restoration efforts by deleting backups before deploying the ransomware payloads on the victims' networks. As Sophos X-Ops incident responders r...
New Veeam RCE flaw lets domain users hack backup servers
BleepingComputer
·Sergiu Gatlan
·Published Jun 17, 2025
·Updated
Affected Software
2 affected components
Veeam Backup & Replication=12
Veeam Backup & Replication=12.3.2.3617
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a newly discovered critical remote code execution vulnerability in Veeam Backup & Replication software.
2
What security implications are discussed in relation to this flaw?
The vulnerability allows domain users to execute arbitrary code on backup servers, posing a significant threat to data integrity and security.
3
What specific version of the software is affected by this vulnerability?
The vulnerability affects Veeam Backup & Replication version 12 and version 12.3.2.3617.
4
What actions has Veeam taken in response to this security flaw?
Veeam has released security updates to address the vulnerabilities, including the critical RCE flaw.
5
How can users protect themselves from the identified security risk?
Users are advised to promptly apply the security updates released by Veeam to safeguard against the vulnerability.