KEVIntel
9.9
CVSS
Critical

CVE-2025-23121

PUBLISHED

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

Exploited in the wild Remote Low complexity No user interaction
Vendor
Veeam
Product
Backup and Recovery
Published
Jun 18, 2025
EPSS

Description

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

CVSS scores

CVSS v3.0 9.9 Critical

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2025-06-18 12:32:38 UTC · Source

SSVC decision points

Exploitation
none
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Jun 18, 2025

Timeline

  • CVE ID Reserved

  • Added to KEVIntel

  • CVE Published to Public