• News/
  • https://www.theregister.com/2025/03/20/infoseccers_criticize_veeam_over_critical/

Infoseccers criticize Veeam over critical RCE vulnerability and a failing blacklist

The Register
·
Connor Jones
·
Published Mar 20, 2025
·
Updated

In patching the latest critical remote code execution (RCE) bug in Backup and Replication, software shop Veeam is attracting criticism from researchers for the way it handles uncontrolled deserialization vulnerabilities. The vendor patched the near-maximum severity CVE-2025-23120 (9.9) on March 19, which can be exploited by any authenticated domain user provided the Veeam server is domain-joined. It affects Backup and Replication 12.3.0.310 and all earlier versions, Veeam said – all supported releases. Usually, when vulnerabilities require authentication before the bad stuff can happen, The Register pops a big warning – a caveat – near the top of a report communicating that fact. They're typically not as dangerous as their pre-auth cousins. However, the severity score speaks for itself, and as watchTowr's Piotr Bazydlo noted in his analysis of the bug, "the authentication requirement is fairly weak." He's referring to the fact that any domain user can exploit the bugs, provided the organization in question doesn't have a hardened Active Directory configuration. Veeam tries to pass some blame onto users by saying the B&R server should never be domain-joined as it goes against its best practices, but as many have already pointed out, barely anyone seems to be aware of this. Also, as Bazydlo and Rapid7 highlighted, Veeam B&R is routinely targeted by ransomware groups, who are usually resourceful enough to gain access to at least one user account within an organization. Further, ...

Read full article

Affected Software

4 affected components
Veeam Backup And Replication=12.3.0.310
Veeam Backup And Replication
Veeam Backup And Replication=12.3.0.310
Veeam Backup And Replication
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution (RCE) vulnerability in Veeam's Backup and Replication software, version 12.3.0.310.

2

What security implications are discussed?

The security implications include the potential for attackers to exploit uncontrolled deserialization vulnerabilities to execute arbitrary code on affected systems.

3

What products or software are affected?

The affected software is Veeam Backup and Replication, specifically version 12.3.0.310.

4

What criticisms have been raised by researchers regarding Veeam?

Researchers criticize Veeam for its ineffective handling of the RCE vulnerability and for the shortcomings in its patching process.

5

What type of vulnerability is the focus of the criticisms?

The focus is on a remote code execution (RCE) vulnerability related to uncontrolled deserialization.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203