PT-2025-11958 · Veeam · Veeam Backup & Replication
Published
2025-03-19
·
Updated
2026-05-04
·
CVE-2025-23120
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Veeam Backup & Replication versions prior to 12.3.1
Description
A deserialization flaw exists in Veeam Backup & Replication, where the application improperly handles serialized data. This allows an authenticated domain user or a member of the local Users group to inject malicious objects or gadgets to execute arbitrary code remotely with SYSTEM-level access. The issue is specifically tied to the
Veeam.Backup.EsxManager.xmlFrameworkDs and Veeam.Backup.Core.BackupSummary classes. This flaw stems from the use of blacklist-based protection mechanisms, which failed to block certain gadget chains. This issue only impacts installations that are joined to an Active Directory domain.Recommendations
Upgrade to version 12.3.1 (build 12.3.1.1139).
Disconnect the backup server from the domain to align with security best practices.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veeam Backup & Replication