Veeam Security Update – 05 February 2025

Veeam has released a security update to fix a critical vulnerability across multiple Veeam products.

The addressed vulnerability could allow the remote attacker to utilize a Man-in-the-Middle attack to execute arbitrary code with root-level permissions and gain access to the affected systems.

Veeam Backup Arbitrary Code Execution Vulnerability (CVE-2025-23114):

  • CVSS: 9.0
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

The affected products:

  • Veeam Backup for Salesforce.
  • Veeam Backup for Nutanix AHV.
  • Veeam Backup for AWS.
  • Veeam Backup for Microsoft Azure.
  • Veeam Backup for Google Cloud.
  • Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization.
Vulnerabilities

CVE-2025-23114

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Veeam Security Update

References