CVE-2025-23121: critical vulnerability in Veeam Backup and Recovery
Published · Updated
33Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.9epss 24%
exploitation probability
24%top 2% of all CVEs
observed exploitation
nono source reports it
In short
A Backup Server allows an authenticated domain user to run arbitrary code remotely. This is critical because attackers with valid domain credentials can fully compromise the backup system and access all backed-up data.
Technical detail
CWE-94 (Code Injection) vulnerability in Backup Server permits remote code execution when an authenticated domain user submits specially crafted input. Exploitation requires valid domain credentials and network access; successful exploitation grants arbitrary code execution with server privileges, enabling data exfiltration and system compromise.
Summary generated and translated by AI from the official description.
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Veeam · Backup and RecoveryRelated CVEs — Veeam Backup and Recovery
In the same product, most dangerous first.
References
https://www.veeam.com/kb4743