Security Update: Veeam Backup and Replication
Vulnerability Name: Veeam Backup and Replication
Platform or Software Package(s) affected: Veeam Backup & Replication Solutions versions 12.3.1.1139 and earlier (CVE-2025-23121)
Criticality: Highly Critical (9.9/10)
Recommended Action: Update to version 12.3.2.3617 immediately
Overview of concern and overview of remediation:
Code is being actively used that allows authenticated domain users to actively bypass the previous CVE patch (CVE-2025-23120) and to perform remote code execution exploitation, which could result in full control of the affected system(s). It is important to realize that an external attacker who has gained access through a phishing attack or other method and has gained access to the network with the rights of a normal non-administrator user may also be able to exploit this vulnerability; the vendor has given this a high rating (9.8/10) for emergency response and patching to the latest version.
Please contact Jeremy Burris at S.R. Snodgrass, P.C. with any questions (jburris@srsnodgrass.com).
Sincerely,
S.R. Snodgrass, P.C.
d/b/a S.R. Snodgrass, A.C. in West Virginia


