CVE-2025-23121 is a critical vulnerability discovered in Veeam Backup & Replication (VBR) that affects domain-joined systems. This vulnerability allows an authenticated but limited privileged domain user to execute unauthorized remote code (RCE) on a VBR server.
The root cause of the vulnerability is the failure of the Veeam Backup server to adequately isolate security boundaries during Windows domain integration. In particular, components that interact with Veeam services are vulnerable to user input at certain checkpoints when authenticated via the domain.
If an attacker already has a domain account (for example, a low-privilege service or user account), they can trigger this vulnerability to run their own commands on the VBR server. This creates significant risk in scenarios such as:
Affected Systems
Veeam Backup & Replication:
All 12.x series versions 12.3.1.1139 and older, as well as older versions out of official support.
Also three patches in conjunction:
IoC’s
-
Recommended Solution(s)
CVE / CWE
CVE-2025-23121
Related Website(s)
* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.
+90 216 504 53 32
Aydınevler Mahallesi,İsmet İnönü Cadddesi,Küçükyalı Ofis Park A Blok,No:20/1 Maltepe İstanbul
+90 312 235 44 51
You can register to our newsletter on the home page to be instantly informed about security vulnerabilities.