CVE-2025-23120 Details
Description
A vulnerability allowing remote code execution (RCE) for domain users.
A remote code execution vulnerability has been identified in Veeam Backup & Replication versions 12.3.0.310 and earlier. This vulnerability allows authenticated domain users to execute arbitrary code on the backup server. The issue arises from a deserialization vulnerability in the .NET Remoting Channel, where Veeam's deserialization mechanism improperly manages a blacklist of disallowed classes. Exploitation is possible by leveraging specific deserialization gadgets available in the Veeam codebase.
Users are advised to upgrade to Veeam Backup & Replication version 12.3.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/ | CISA-ADP | ExploitThird Party Advisory |
| https://www.veeam.com/kb4724 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| veeam veeam backup & replication | >= 12.0.0.1402, < 12.3.1.1139 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2025 | Initial Analysis | [email protected] |
| Mar 20, 2025 | CVE Modified | CISA-ADP |
| Mar 20, 2025 | New CVE Received | [email protected] |