Veeam Backup & Replication: Critical RCE Patched
ID: efb903b3-b134-5b06-8f0e-bbc6e92063f5
STIX ID: report--efb903b3-b134-5b06-8f0e-bbc6e92063f5
Feed Name: Kudelski Security
Veeam released security updates addressing three vulnerabilities: CVE-2025-23121 (critical RCE, CVSS 9.9) affecting domain-joined Backup & Replication servers, CVE-2025-24286 (high, allows Backup Operator to modify jobs potentially leading to code execution), and CVE-2025-24287 (medium local privilege escalation in Veeam Agent for Windows); exploitation requires authentication and Veeam recommends patching to VBR 12.3.2 (build 12.3.2.3617) and Agent 6.3.2 (build 6.3.2.1205) and considering management isolation from production AD.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
