Skip to main content

Vendor: Veeam
Product: Veeam Backup & Replication / Veeam Agent for Microsoft Windows
CVE IDs: CVE-2025-48982, CVE-2025-48983, CVE-2025-48984

Severity:

  • CVE-2025-48983: CVSS v3: 9.9 — Remote Code Execution (RCE) via the Mount service
  • CVE-2025-48984: CVSS v3: 9.9 — Remote Code Execution (RCE) via the backup server
  • CVE-2025-48982: CVSS v3: 7.3 — Local privilege escalation during restoration of malicious files

Description:
Two Critical vulnerabilities have been discovered in Veeam Backup & Replication v12 and one High in Veeam Agent for Microsoft Windows:

  • CVE-2025-48983: A flaw in the Mount service allows remote arbitrary code execution on backup hosts by an authenticated domain user.
  • CVE-2025-48984: A similar vulnerability enables remote code execution on the Veeam Backup server.
  • CVE-2025-48982: Local privilege escalation is possible when an administrator restores a malicious file using Veeam Agent for Windows.

These vulnerabilities affect only domain-joined servers; Veeam appliances and the upcoming version 13 are not impacted from an architectural standpoint.

Affected Versions:

  • Veeam Backup & Replication: Versions ≤ 12.3.2.3617 and all versions ≤ 12
  • Veeam Agent for Windows: Versions ≤ 6.3.2.1205 and all versions < 6

Fix:

  • Veeam Backup & Replication: Update to version 12.3.2.4165 or later
  • Veeam Agent for Windows: Update to version 6.3.2.1302 or later

Official Link: https://www.veeam.com/kb4771

I like to repeat myself once more: Keep Veeam outside of Active Directory (I even slowly step away from management domains due to the huge workload of securing and and hardening that domain besides the production domain). 😊


@lukas.k accordingly :-)


@Stabz Thank you for the summary.


Any ideas why setup.exe only offers to modify the installation instead of update? The installation is not on the latest version...


Any ideas why setup.exe only offers to modify the installation instead of update? The installation is not on the latest version...

Please, see my comment in the link below. It shows when to use the exe or the ISO!

 


I was little bit confused that date was 20251006 of patch 4165, but released was on Monday 13.10.25, so I was looking if additional patch is needed, but looks not


Any ideas why setup.exe only offers to modify the installation instead of update? The installation is not on the latest version...

@Chris.Childerhose, this is one the caveats similar to the ISO when not used correctly 


Any ideas why setup.exe only offers to modify the installation instead of update? The installation is not on the latest version...

@Chris.Childerhose, this is one the caveats similar to the ISO when not used correctly 

Yes I get updating from other versions you need the full ISO but EXE/ISO if you are on the latest release works to update.  That is all I was saying as you assume everyone is on the latest patch right. 😋


Any ideas why setup.exe only offers to modify the installation instead of update? The installation is not on the latest version...

@Chris.Childerhose, this is one the caveats similar to the ISO when not used correctly 

Yes I get updating from other versions you need the full ISO but EXE/ISO if you are on the latest release works to update.  That is all I was saying as you assume everyone is on the latest patch right. 😋

Note really, my focus was on 12.3.2.3617 to 12.3.2.4165! The ISO does not work for this. Let’s take this offline.