By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Veeam RCE bug lets domain users hack backup servers, patch now
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Veeam RCE bug lets domain users hack backup servers, patch now
Tech News

Veeam RCE bug lets domain users hack backup servers, patch now

By admin 3 Min Read
Share
SHARE

Veeam has patched a critical remote code execution vulnerability tracked as CVE-2025-23120 in its Backup & Replication software that impacts domain-joined installations.

The flaw was disclosed yesterday and affects Veeam Backup & Replication version 12.3.0.310 and all earlier version 12 builds. The company fixed it in version 12.3.1 (build 12.3.1.1139), which was released yesterday.

According to a technical writeup by watchTowr Labs, who discovered the bug, CVE-2025-23120 is a deserialization vulnerability in the Veeam.Backup.EsxManager.xmlFrameworkDs and Veeam.Backup.Core.BackupSummary .NET classes.

A deserialization flaw is when an application improperly processes serialized data, allowing attackers to inject malicious objects, or gadgets, that can execute harmful code.

Last year, while fixing a previous deserialization RCE flaw discovered by researcher Florian Hauser. To fix the flaw, Veeam introduced a blacklist of known classes or objects that could be exploited.

However, watchTowr was able to find a different gadget chain that was not blacklisted to achieve remote code execution.

“Anyway, you’ve probably guessed where this is going today – it seems Veeam, despite being a ransomware gang’s favourite play toy – didn’t learn after the lesson given by Frycos in previous research published. You guessed it – they fixed the deserialization issues by adding entries to their deserialization blacklist.”

The good news is that the flaw only impacts Veeam Backup & Replication installations that are joined to a domain. The bad news is that any domain user can exploit this vulnerability, making it easily exploitable in those configurations.

Unfortunately, many companies have joined their Veeam server to a Windows domain, ignoring the company’s long-standing best practices.

Ransomware gangs have told BleepingComputer in the past that Veeam Backup & Replication servers are always targets, as it allows them an easy way to steal data and block restoration efforts by deleting backups.

This flaw would make Veeam installs even more valuable due to the ease with which threat actors can breach the servers.

While there are no reports of this flaw being exploited in the wild, watchTowr has shared enough technical details that it would not be surprising to see a proof-of-concept (PoC) released soon.

Those companies using Veeam Backup & Replication should make it a priority to upgrade to 12.3.1 as soon as possible.

Furthermore, given ransomware gangs’ interest in this application, it is strongly advised to review Veeam’s best practices and disconnect the server from your domain.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

You Might Also Like

Apple AI Pin Specs Leak: Dual Cameras, No Screen & More

The diverse responsibilities of a principal software engineer

OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters

Google’s Fitbit Tease has me More Excited for Garmin’s Whoop Rival

Why the TCL NXTPAPER 14 Is One of the Best Tablets for Musicians and Sheet Music Reading

TAGGED: CVE-2025-23120, Remote Code Execution, Security Update, Veeam, Veeam Backup & Replication, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Ex-Man City star explains why Pep Guardiola will leave 'before next season' as replacement named
Next Article ‘We Don’t Want an AI Demo, We Want Answers’: Federal Workers Grill Trump Appointee During All-Hands
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
Business
Apple AI Pin Specs Leak: Dual Cameras, No Screen & More
Tech News
A ‘glass-like’ battlefield: German Army chief on the future of warfare
World News
Polymarket Sees Record $153M Daily Volume After Chainlink Integration
Crypto
Natasha Lyonne Then & Now: See Before & After Photos of the Actress Here
Celebrity
Cult Hit Doki Doki Literature Club Fights Removal From Google Play Store Over ‘Depiction Of Sensitive Themes’
Gaming News
Dead as Disco Launches Into Early Access on May 5th, Groovy New Gameplay Released
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
April 10, 2026
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?