What Happened

CVE-2025-23120 (CVSS 9.9) was disclosed by watchTowr Labs in March 2025. The vulnerability affects Veeam Backup & Replication 12.x and allows any authenticated domain user — not just Veeam administrators — to achieve remote code execution on the backup server via unsafe deserialization of attacker-controlled data.

Why Backup Servers Are Prime Targets

Ransomware operators follow a consistent playbook:

  1. Gain initial access via phishing or CVE exploitation
  2. Establish persistence and escalate privileges
  3. Destroy or encrypt backups before detonating ransomware
  4. Demand ransom knowing victims cannot restore

Veeam servers are often domain-joined but receive fewer security controls than domain controllers, making them attractive targets.

Recommended Actions

  1. Apply Veeam B&R patch 12.3.1.1139 or later immediately
  2. Isolate the Veeam server from general domain access — use a dedicated service account, not domain admin
  3. Enable immutable backup repositories (Veeam Hardened Repository)
  4. Consider air-gapped or offline backup copies (3-2-1 rule)
  5. Restrict TCP 9392 (Veeam Enterprise Manager) access via firewall