Veeam has addressed a critical remote code execution vulnerability (CVE-2025-23120) affecting domain-joined installations of its Backup & Replication software. The flaw impacts version 12.3.0.310 and all earlier version 12 builds, with a fix now available in version 12.3.1 (build 12.3.1.1139).
## Technical Details
According to watchTowr Labs, who discovered the bug, CVE-2025-23120 is a deserialization vulnerability in the Veeam.Backup.EsxManager.xmlFrameworkDs and Veeam.Backup.Core.BackupSummary .NET classes. This type of flaw occurs when applications improperly process serialized data, allowing attackers to inject malicious objects that can execute harmful code.
The vulnerability emerged despite Veeam’s previous attempts to fix a similar issue by implementing a blacklist of known exploitable classes. However, researchers found an alternative gadget chain that bypassed this protection.
## Impact and Risk
The vulnerability only affects Veeam Backup & Replication installations joined to a domain, but in such configurations, any domain user can exploit it. This is particularly concerning as many organizations have connected their Veeam servers to Windows domains despite the company’s longstanding recommendations against this practice.
Ransomware gangs have historically targeted Veeam Backup & Replication servers as they provide opportunities to steal data and prevent recovery by deleting backups. This new vulnerability makes these installations even more attractive targets due to the ease of exploitation.
## Recommendations
While no active exploitation has been reported yet, detailed technical information has been published that could lead to proof-of-concept exploits appearing soon. Organizations using Veeam Backup & Replication should:
1. Upgrade to version 12.3.1 immediately
2. Review Veeam’s best practices documentation
3. Consider disconnecting Veeam servers from domain environments
Given ransomware operators’ interest in this application, prompt remediation is strongly advised.
