CVE-2025-23120: critical vulnerability in Veeam Backup and Recovery
Published
33Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.9epss 24%
exploitation probability
24%top 2% of all CVEs
observed exploitation
nono source reports it
In short
A critical flaw allows attackers to run arbitrary code on computers within a network domain. This puts all connected machines at serious risk of being compromised.
Technical detail
CWE-502 (Deserialization of Untrusted Data) enables remote code execution for domain-authenticated users through unsafe deserialization mechanisms. An attacker with domain access can craft malicious serialized objects to achieve arbitrary code execution on target systems.
Summary generated and translated by AI from the official description.
A vulnerability allowing remote code execution (RCE) for domain users.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Veeam · Backup and RecoveryRelated CVEs — Veeam Backup and Recovery
In the same product, most dangerous first.