{"id":1767,"date":"2025-02-05T10:03:34","date_gmt":"2025-02-05T10:03:34","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/05\/critical-veeam-backup-vulnerability-let-attackers-execute-arbitrary-code-to-gain-root-access\/"},"modified":"2025-02-05T10:03:34","modified_gmt":"2025-02-05T10:03:34","slug":"critical-veeam-backup-vulnerability-let-attackers-execute-arbitrary-code-to-gain-root-access","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/05\/critical-veeam-backup-vulnerability-let-attackers-execute-arbitrary-code-to-gain-root-access\/","title":{"rendered":"Critical Veeam Backup Vulnerability Let Attackers Execute Arbitrary Code to Gain Root Access"},"content":{"rendered":"<p>    Critical Veeam Backup Vulnerability Let Attackers Execute Arbitrary Code to Gain Root Access<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical vulnerability, identified as CVE-2025-23114, has been discovered in the Veeam Updater component, a key element of multiple <a href=\"https:\/\/cybersecuritynews.com\/veeam-azure-backup-solution-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Veeam backup solutions<\/a>.\u00a0<\/p>\n<p>This flaw enables attackers to execute arbitrary code on affected servers through a Man-in-the-Middle (MitM) attack, potentially granting root-level permissions.\u00a0<\/p>\n<p>The vulnerability has been assigned a severity score of 9.0, underscoring its significant risk.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Overview of the Veeam Backup Vulnerability\u00a0<\/strong><\/h2>\n<p>The vulnerability exists due to insecure communication channels used by the Veeam Updater component when transmitting sensitive data.\u00a0<\/p>\n<p>Exploiting this flaw allows attackers positioned between the vulnerable appliance and its <a href=\"https:\/\/cybersecuritynews.com\/microsoft-re-releases-exchange-server-security-update\/\" target=\"_blank\" rel=\"noreferrer noopener\">update<\/a> server to intercept and interfere with update requests.\u00a0<\/p>\n<p>By injecting malicious code, attackers can gain complete control over the system, leading to potential data breaches, ransomware deployment, or persistent access within an organization\u2019s infrastructure.<\/p>\n<p>This issue impacts various Veeam products, including:<\/p>\n<ul class=\"wp-block-list\">\n<li>Veeam Backup for Salesforce (versions 3.1 and older)<\/li>\n<li>Veeam Backup for Nutanix AHV (versions 5.0 and 5.1)<\/li>\n<li>Veeam Backup for AWS (versions 6a and 7)<\/li>\n<li>Veeam Backup for <a href=\"https:\/\/cybersecuritynews.com\/azure-ai-face-service-vulnerability-lets-attackers-gain-network-access\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Azure<\/a> (versions 5a and 6)<\/li>\n<li>Veeam Backup for Google Cloud (versions 4 and 5)<\/li>\n<li>Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization (versions 3, 4.0, and 4.1)<\/li>\n<\/ul>\n<p>Veeam has <a href=\"https:\/\/www.veeam.com\/kb4712\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released<\/a> updates addressing CVE-2025-23114 by patching the affected Veeam Updater component in newer versions of its software.\u00a0<\/p>\n<p>Automatic updates are enabled by default for all actively supported backup appliances, ensuring that most users will receive the fix without manual intervention.<\/p>\n<p>The following updated versions of the Veeam Updater component resolve the vulnerability:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Product\u00a0<\/strong><\/td>\n<td><strong>Fixed Updater Version<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Veeam Backup for Salesforce<\/td>\n<td>7.9.0.1124<\/td>\n<\/tr>\n<tr>\n<td>Veeam Backup for Nutanix AHV<\/td>\n<td>9.0.0.1125<\/td>\n<\/tr>\n<tr>\n<td>Veeam Backup for AWS<\/td>\n<td>9.0.0.1126<\/td>\n<\/tr>\n<tr>\n<td>Veeam Backup for Microsoft Azure<\/td>\n<td>9.0.0.1128<\/td>\n<\/tr>\n<tr>\n<td>Veeam Backup for <a href=\"https:\/\/cybersecuritynews.com\/google-to-issue-cves\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Cloud<\/a>\n<\/td>\n<td>9.0.0.1128<\/td>\n<\/tr>\n<tr>\n<td>Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization<\/td>\n<td>9.0.0.1127<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Organizations using older versions of affected products are at heightened risk if updates are not promptly applied. However, deployments running Veeam Backup &amp; Replication version 12.3 with updated appliances are unaffected.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Mitigation Steps<\/strong><\/h2>\n<p>To protect against this critical vulnerability:<\/p>\n<ul class=\"wp-block-list\">\n<li>Use the built-in Veeam Updater tool to ensure your appliance is running the fixed version.<\/li>\n<li>Check the version of your Veeam Updater component by navigating to the update history or reviewing logs in &lt;log_bundle&gt;\/veeam\/veeam-updater\/updater.log.<\/li>\n<li>Ensure that all backup appliances are updated to the latest unaffected versions<\/li>\n<\/ul>\n<p>This highlights the importance of maintaining up-to-date <a href=\"https:\/\/cybersecuritynews.com\/abandoned-aws-s3-buckets\/\" target=\"_blank\" rel=\"noreferrer noopener\">software<\/a> in critical infrastructure systems like backup solutions.\u00a0<\/p>\n<p>Administrators should ensure their systems are patched promptly while implementing additional security measures such as network monitoring and isolating backup appliances from external access wherever possible.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_feb&amp;utm_medium=article&amp;utm_campaign=3soc-challenges&amp;utm_content=plans&amp;utm_term=040225\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/critical-veeam-backup-vulnerability\/\">Critical Veeam Backup Vulnerability Let Attackers Execute Arbitrary Code to Gain Root Access<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/critical-veeam-backup-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Veeam Backup Vulnerability Let Attackers Execute Arbitrary Code to Gain Root Access A critical vulnerability, identified as CVE-2025-23114, has been discovered in the Veeam Updater component, a key element of multiple Veeam backup solutions.\u00a0 This flaw enables attackers to execute arbitrary code on affected servers through a Man-in-the-Middle (MitM) attack, potentially granting root-level permissions.\u00a0 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131],"tags":[130],"class_list":["post-1767","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1767"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1767"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1767\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1767"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1767"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1767"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}