Veeam Security Update – 20 March 2025

Veeam has released a security update to fix a critical vulnerability across Veeam Backup & Replication systems.

The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected system.

Veeam Backup Arbitrary Code Execution Vulnerability (CVE-2025-23120):

  • CVSS: 9.9
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Access

The affected products:

  • Veeam Backup & Replication 12.3.0.310 and all earlier version 12 builds.
Vulnerabilities

CVE-2025-23120

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Veeam Security Update

References