Gbhackers Critical Vulnerability in Veeam Backup Allows Remote Code Execution
Article Content
- •CVE-2025-64393 allows remote code execution for low-privileged users in Veeam Backup.
- •The flaw has a CVSS score of 9.4 and affects version 12.3.2.4854 and earlier builds.
- •Veeam has released patches and confirmed that version 13 is not affected.
Veeam has released security updates for a critical vulnerability (CVE-2025-64393) in its Backup & Replication software, allowing low-privileged users to execute remote code on backup servers. This flaw, with a CVSS score of 9.4, affects version 12.3.2.4854 and earlier builds but is not present in version 13. Exploitation requires an authenticated account with the Backup Viewer role and involves insecure deserialization of untrusted data via the Mount Service. The vulnerability was reported through HackerOne, but there are no confirmations of exploitation in the wild. Additionally, three other vulnerabilities were addressed in the same update, with severity ratings ranging from medium to high. Administrators are advised to check their installed builds and apply the necessary updates promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2025-64392 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of Veeam are affected?
How critical is the vulnerability?
What should I do to protect my systems?
Continue Reading
Multiple WordPress Plugins Face Vulnerabilities Requiring Immediate Updates Three WordPress plugins have been reported with vulnerabilities: the GiveWP plugin (version 4.16.9) has a Cross Site Scripting (XSS) vulnerability, while both the Siteskite (version 2.1.8) and Cartflows (version 3.2.0) plugins have Remote Code Execution (RCE) vulnerabilities. The XSS vulnerability allows attackers to…