Veeam Backup & Replication and Veeam Agent for Windows Backup Job Modification Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in Veeam Backup & Replication versions 12.3.1 and earlier, as well as Veeam Agent for Microsoft Windows versions 6.3.1 and earlier. This vulnerability allows an authenticated user with the Backup Operator role to modify backup jobs, potentially leading to the execution of arbitrary code.

Impact

Exploitation of this vulnerability could result in unauthorized modification of backup jobs and execution of arbitrary code on the affected system.

Remediation

Users can upgrade to Veeam Backup & Replication 12.3.2 or Veeam Agent for Microsoft Windows 6.3.2 to address this vulnerability.

Added: Jun 19, 2025, 12:21 AM
Updated: Jun 19, 2025, 12:21 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
10.0
exploitability
4.9
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.