logo

Infoseccers criticize Veeam over critical RCE vulnerability and a failing blacklist

ID: c3911693-0617-5d85-b0f8-490229ddfe62

STIX ID: report--c3911693-0617-5d85-b0f8-490229ddfe62

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-03-20

Date Updated: 2026-04-26

Author: Connor Jones

...
...

The article reports on a near-critical RCE in Veeam Backup & Replication (CVE-2025-23120, 9.9) patched by Veeam, and researchers' criticism that Veeam's blocklist-based deserialization mitigation is inadequate; the flaw can be exploited by any authenticated domain user on domain-joined servers and is particularly concerning because ransomware actors routinely target Veeam deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.