SB2025101450 - Two remote code execution vulnerabilities in Veeam Backup & Replication



SB2025101450 - Two remote code execution vulnerabilities in Veeam Backup & Replication

Published: October 14, 2025

Security Bulletin ID SB2025101450
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2025-48984)

The vulnerability allows a remote user to execute arbitrary code on the system.

The vulnerability exists due to an unspecified error. An authenticated domain user can execute arbitrary code on the Backup Server.


2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2025-48983)

The vulnerability allows a remote user to execute arbitrary code on the system.

The vulnerability exists due to an unspecified error in the Mount service. An authenticated domain user can execute arbitrary code on the Backup infrastructure hosts.


Remediation

Install update from vendor's website.