Critical Veeam Backup RCE Flaws Allow Remote Execution of Malicious Code
Veeam has issued a critical security update addressing multiple remote code execution (RCE) vulnerabilities in Veeam Backup & Replication version 12. These vulnerabilities could enable authenticated domain users to execute malicious code on backup…
Veeam has issued a critical security update addressing multiple remote code execution (RCE) vulnerabilities in Veeam Backup & Replication version 12. These vulnerabilities could enable authenticated domain users to execute malicious code on backup servers and infrastructure hosts. Immediate application of this patch is necessary to mitigate potential breaches.
The most severe vulnerabilities impact domain-joined Veeam Backup & Replication v12 installations:
CVE-2025-48983: This vulnerability targets the Mount service on backup infrastructure hosts, allowing an authenticated domain user to execute arbitrary code remotely. It has a CVSS v3.1 score of 9.9. CVE-2025-48984: An authenticated domain user can achieve RCE on the primary backup server. This vulnerability also has a CVSS v3.1 score of 9.9.
Additionally, a high-severity local privilege escalation vulnerability, CVE-2025-48982 , exists in Veeam Agent for Microsoft Windows. This can be exploited if an administrator restores a malicious file, leading to elevated system privileges. It has a CVSS v3.1 score of 7.3.
All identified vulnerabilities have been rectified in the Veeam Backup & Replication 12.3.2.4165 patch and the Veeam Agent for Microsoft Windows 6.3.2.1302 update. Veeam’s Vulnerability Disclosure Program ensures timely patch development and provides mitigation instructions. Organizations are advised to immediately apply the latest updates and verify that all systems are running the updated software versions.
Veeam has issued a critical security update addressing multiple remote code execution (RCE) vulnerabilities in Veeam Backup & Replication version 12.
Administrators should consult the Veeam Backup & Replication Security Best Practice Guide to minimize attack surfaces and ensure robust security configurations. Regular audits and strict access controls are recommended to further mitigate exploitation risks.
CVE ID Description Severity CVSS Score
CVE-2025-48983 RCE via Mount service on backup infrastructure hosts by authenticated user Critical 9.9
CVE-2025-48984 RCE on backup server by authenticated domain user Critical 9.9
CVE-2025-48982 Local privilege escalation in Veeam Agent for Microsoft Windows when restoring malicious file High 7.3
Organizations utilizing Veeam Backup & Replication version 12 or Veeam Agent for Windows should ensure the patches released on October 14, 2025, are applied. Prompt updates are crucial to defend against known exploits and unauthorized code execution in backup environments.
Based on reporting by GBHackers.
