Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2025-64393: Veeam Backup & Replication lets viewers run code as SYSTEM
CVE-2025-64393 · published 3 days ago
Summary
The Backup Viewer feature in Veeam Backup & Replication can be tricked into running any program with the highest system privileges on the backup server. This could allow an attacker to take control of the server and access all backed‑up data. Install the latest patch from Veeam or disable the Backup Viewer function if you do not need it.
What to do
- Update veeam backup and replication to version 12.3.2.4934 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| veeam | backup and replication | < 12.3.2.4934 |
Original advisory text
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.
References
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta