CVE-2025-23120
CVE-2025-23120
Vexday Risk Score
33Attention
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.9EPSS 18.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In short
A critical flaw allows attackers to run arbitrary code on computers within a network domain. This puts all connected machines at serious risk of being compromised.
Technical detail
CWE-502 (Deserialization of Untrusted Data) enables remote code execution for domain-authenticated users through unsafe deserialization mechanisms. An attacker with domain access can craft malicious serialized objects to achieve arbitrary code execution on target systems.
Summary generated and translated by AI from the official description.
A vulnerability allowing remote code execution (RCE) for domain users.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Veeam · Backup and RecoveryWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →