Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2025-64393: Veeam Backup & Replication lets viewers run code as SYSTEM

CVE-2025-64393 · published 3 days ago
Summary

The Backup Viewer feature in Veeam Backup & Replication can be tricked into running any program with the highest system privileges on the backup server. This could allow an attacker to take control of the server and access all backed‑up data. Install the latest patch from Veeam or disable the Backup Viewer function if you do not need it.

What to do
  • Update veeam backup and replication to version 12.3.2.4934 or later.
Affected software
VendorProductAffected versions
veeam backup and replication < 12.3.2.4934
Original advisory text
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2025-64393 · MITRE
Track software like this
Free during beta