What Happened
CVE-2025-23120 (CVSS 9.9) was disclosed by watchTowr Labs in March 2025. The vulnerability affects Veeam Backup & Replication 12.x and allows any authenticated domain user — not just Veeam administrators — to achieve remote code execution on the backup server via unsafe deserialization of attacker-controlled data.Why Backup Servers Are Prime Targets
Ransomware operators follow a consistent playbook:
- Gain initial access via phishing or CVE exploitation
- Establish persistence and escalate privileges
- Destroy or encrypt backups before detonating ransomware
- Demand ransom knowing victims cannot restore
Veeam servers are often domain-joined but receive fewer security controls than domain controllers, making them attractive targets.
Recommended Actions
- Apply Veeam B&R patch 12.3.1.1139 or later immediately
- Isolate the Veeam server from general domain access — use a dedicated service account, not domain admin
- Enable immutable backup repositories (Veeam Hardened Repository)
- Consider air-gapped or offline backup copies (3-2-1 rule)
- Restrict TCP 9392 (Veeam Enterprise Manager) access via firewall