News Current vulnerability in Veeam Backup & Replication (CVE-2025-23120) for domain-joined backup servers

Bernd Hanebuth & Markus Stumpf — 20. Mar 2025

Aktuelle Sicherheitslücke in Veeam Backup & Replication (CVE-2025-23120) für Domain-angebundene Backupserver

On 19 March 2025, Veeam published the note with a score of 9.9.

Update of our information

During installation of the update provided by Veeam via UpdateISO, various error messages may occur.

We have made experiences with a customer, which could be interesting for many users of Veeam Backup & Replication in the course of troubleshooting.

Read our update now:.

1. error message

‘Setup has detected inconsistent configuration: some Veeam Backup & Replication components are missing. Remove the installed Veeam Backup & Replication components manually and start the setup wizard again.’

There is already a Veeam KB article on this, which is useful. It is important that the customer checks in advance whether the Veeam Entra ID plugin is installed. There is this Veeam Knowledge Base article on this: https://www.veeam.com/kb4725.

2. error message

This error message is not entirely clear. The update ends with a ‘Fatal Error’.

Experience has shown that it helps to check the following

  • The start type of the Veeam services MUST be set to ‘manual’ (and not ‘disabled’).
  • The services ‘Veeam Backup Update Service’ and ‘Veeam Guest Catalog Service’ must be running under the ‘local system account’.

Vulnerability in Veeam Backup & Replication | 12 | 12.1 | 12.2 | 12.3

There is an actual vulnerability in Veeam Backup & Replication (CVE-2025-23120) for domain-joined backup servers.

On 19 March 2025, Veeam published the vulnerability in the article https://www.veeam.com/kb4724 with a score of 9.9.

Domain-attached backup servers are at risk of remote code execution (RCE).

The latest build, or full documentation of the changes, can be found here: https://www.veeam.com/kb4696.

Veeam also released a hotfix on 21 March at https://www.veeam.com/kb4724. Attention: This is only compatible with build 12.3.0.310!

Note

Domain-joining backup servers is against Veeam best practices.

Using the Security and Compliance Analyser, you can quickly check if there are any deviations from Veeam best practices in your environment.

Security & Compliance Analyser:

https://helpcenter.veeam.com/docs/backup/vsphere/best_practices_analyzer.html?zoom_highlight=%22Backup%20server%20should%20not%20be%20a%20part%20of%20the%20production%20domain%22&ver=120

What are remote code execution vulnerabilities?

Attackers use such vulnerabilities to execute arbitrary commands without having a valid login and authorisation on the affected server. To do this, they use vulnerabilities in programmes that are already installed on the server.

This is used by attackers as an entry point for compromising the affected servers, but can also lead to further manipulation of these systems, including encryption.

Further information can be found on Wikipedia: https://de.wikipedia.org/wiki/Remote_Code_Execution

Looking to the future

Veeam is currently working intensively on V13, which should be available in the next few months. One highlight will be the introduction of the Veeam Backup and Replication Server as a Linux appliance. Veeam is thus further strengthening cyber resilience by eliminating the Windows dependency of the backup system.

A preview and further information can be discussed in the Veeam Community

https://community.veeam.com/blogs-and-podcasts-57/a-first-look-at-veeam-backup-replication-v13-linux-based-and-web-console-awesomeness-9406?tid=9406&fid=57

Veeam V13 Changes Summary Blog

https://community.veeam.com/blogs-and-podcasts-57/v13-changes-summery-9544?tid=9544&fid=57

Are you affected?

If this scenario applies to your environment, we will be happy to advise and support you in adapting accordingly.

Sources

CVE-2025-23120: https://www.veeam.com/kb4724

Hotfix: https://www.veeam.com/kb4696

Security & Compliance Analyzer: https://helpcenter.veeam.com/docs/backup/vsphere/best_practices_analyzer.html?zoom_highlight=%22Backup%20server%20should%20not%20be%20a%20part%20of%20the%20production%20domain%22&ver=120

You were interested in this, then you may also be interested in...