Saturday, September 12, 2026

Critical Veeam Backup RCE Flaws Allow Remote Execution of Malicious Code

Veeam has released an urgent security patch to address multiple critical remote code execution (RCE) vulnerabilities in Veeam Backup & Replication version 12.

These flaws could allow authenticated domain users to run malicious code on backup servers and infrastructure hosts. With attackers likely to reverse-engineer the patch, organizations must apply the update without delay to avoid potential breaches.

Two of the most severe vulnerabilities affect domain-joined Veeam Backup & Replication v12 installations.

CVE-2025-48983 targets the Mount service on backup infrastructure hosts. An authenticated domain user can exploit this flaw to execute arbitrary code remotely, posing a critical risk with a CVSS v3.1 score of 9.9.

Similarly, CVE-2025-48984 allows RCE on the primary backup server by an authenticated domain user, also rated 9.9.

Both issues were reported by external researchers CODE WHITE in the case of CVE-2025-48983, and Sina Kheirkhah (@SinSinology) alongside Piotr Bazydlo (@chudyPB) of watchTowr for CVE-2025-48984.

Unsupported product versions are untested and should be considered vulnerable until upgrades are applied.

In addition to the critical RCE flaws, a high-severity local privilege escalation vulnerability exists in Veeam Agent for Microsoft Windows.

Identified as CVE-2025-48982, this issue can be triggered if an administrator restores a malicious file crafted by an attacker, leading to elevated privileges on the system.

With a CVSS v3.1 score of 7.3, this flaw was reported anonymously through the Trend Zero Day Initiative. Although less severe than RCE, it still demands prompt patching to prevent privilege abuse.

All three vulnerabilities have been addressed in the Veeam Backup & Replication 12.3.2.4165 patch and the Veeam Agent for Microsoft Windows 6.3.2.1302 update.

 Veeam’s Vulnerability Disclosure Program ensures that once a flaw is found, a patch is developed and published along with mitigation instructions. However, attackers often analyze patches to discover exploits against unpatched systems.

Consequently, organizations must install the latest builds immediately and verify that all backup servers and infrastructure hosts are running the updated software.

Veeam provides a detailed security best practice guide that covers hardening domain and workgroup deployments.

Administrators should review configuration settings to minimize attack surfaces and follow the recommendations in the Veeam Backup & Replication Security Best Practice Guide.

Regular auditing of domain-joined servers and strict access controls will further reduce the risk of exploitation.

CVE IDDescriptionSeverityCVSS Score
CVE-2025-48983RCE via Mount service on backup infrastructure hosts by authenticated userCritical9.9
CVE-2025-48984RCE on backup server by authenticated domain userCritical9.9
CVE-2025-48982Local privilege escalation in Veeam Agent for Microsoft Windows when restoring malicious fileHigh7.3

Organizations using Veeam Backup & Replication version 12 or Veeam Agent for Windows should verify and apply the patches released on October 14, 2025.

Ensuring timely updates is the most effective defense against known exploits and unauthorized code execution in backup environments.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Related Articles

Recent News