SB2025101450 - Two remote code execution vulnerabilities in Veeam Backup & Replication
Published: October 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2025-48984)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to execute arbitrary code on the system.
The vulnerability exists due to an unspecified error. An authenticated domain user can execute arbitrary code on the Backup Server.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2025-48983)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to execute arbitrary code on the system.
The vulnerability exists due to an unspecified error in the Mount service. An authenticated domain user can execute arbitrary code on the Backup infrastructure hosts.
Remediation
Install update from vendor's website.