Veeam has patched a critical remote code execution vulnerability tracked as CVE-2025-23120 in its Backup & Replication software that impacts domain-joined installations. The flaw was disclosed yesterday and affects Veeam Backup & Replication version 12.3.0.310 and all earlier version 12 builds. The company fixed it in version 12.3.1 (build 12.3.1.1139), which was released yesterday. According to a technical writeup by watchTowr Labs, who discovered the bug, CVE-2025-23120 is a deserialization vulnerability in the Veeam.Backup.EsxManager.xmlFrameworkDs and Veeam.Backup.Core.BackupSummary .NET classes. A deserialization flaw is when an application improperly processes serialized data, allowing attackers to inject malicious objects, or gadgets, that can execute harmful code. Last year, while fixing a previous deserialization RCE flaw discovered by researcher Florian Hauser. To fix the flaw, Veeam introduced a blacklist of known classes or objects that could be exploited. However, watchTowr was able to find a different gadget chain that was not blacklisted to achieve remote code execution. "Anyway, you've probably guessed where this is going today - it seems Veeam, despite being a ransomware gang's favourite play toy - didn't learn after the lesson given by Frycos in previous research published. You guessed it - they fixed the deserialization issues by adding entries to their deserialization blacklist." The good news is that the flaw only impacts Veeam Backup & Replication insta...
Veeam RCE bug lets domain users hack backup servers, patch now
BleepingComputer
·Lawrence Abrams
·Published Mar 20, 2025
·Updated
Affected Software
4 affected components
Veeam Backup & Replication=12.3.0.310
Veeam Backup & Replication=12
Veeam Backup & Replication=12.3.0.310
Veeam Backup & Replication=12
Frequently Asked Questions
1
What vulnerability is discussed in this article?
The article discusses a critical remote code execution vulnerability tracked as CVE-2025-23120 in Veeam Backup & Replication software.
2
Who is impacted by this vulnerability?
Domain-joined installations of Veeam Backup & Replication are impacted by this vulnerability.
3
What version of Veeam Backup & Replication is affected?
The affected version of Veeam Backup & Replication is 12.3.0.310 and version 12.
4
What can attackers potentially do due to this vulnerability?
Attackers can exploit this vulnerability to hack backup servers through remote code execution.
5
What should users of Veeam Backup & Replication do in response to this article?
Users should apply the necessary patches provided by Veeam to mitigate the vulnerability immediately.