External risk intelligence

Veeam Backup & Replication Mount Service Remote Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2025-48983

Veeam Backup & Replication is typically deployed within protected internal infrastructure or management networks. While the service is network-reachable within the environment, it is not designed to be exposed directly to the public internet, and access is generally restricted to authenticated domain users within the corporate perimeter.

Remote Code Execution

Veeam Backup \& Replication

12.0.0.1402 to before 12.3.2.4165

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability found in Veeam Backup & Replication's Mount service. The issue allows authenticated users within your domain to potentially execute malicious code remotely on backup infrastructure hosts. Given the nature of backup systems, this could have significant implications for data integrity and system security. The primary concern is to confirm if this specific technology is in use and assess potential exposure.

  • Authenticated users can run malicious code remotely.
  • Backup systems are central to business continuity.
  • Confirm relevance and assess exposure to backups.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access to a Veeam Backup & Replication domain could target the Mount service. Exploiting this service could allow an attacker to execute arbitrary code on the backup infrastructure hosts, potentially leading to a complete compromise of the backup environment.

  • Authenticated domain user access required.
  • Vulnerability in the Mount service.
  • Remote code execution on backup hosts.

Live Threat

Current exploitation, exposure, and threat context

A vulnerability in Veeam Backup & Replication's Mount service could allow an authenticated domain user to execute arbitrary code on backup infrastructure hosts. This could impact the integrity and availability of backup data and services when supported by the advisory's conditions.

  • Backup infrastructure hosts.
  • Remote code execution.
  • Compromise of backup data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Veeam Backup & Replication, likely managed by infrastructure or platform teams responsible for backup operations. The initial focus should be on identifying all deployed instances, assessing their network reachability and business criticality, and confirming the designated owner for remediation.

  • Infrastructure or Platform teams should own remediation.
  • Verify affected systems and their exposure.
  • Plan maintenance for patching and testing.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Veeam Backup & Replication?

Veeam Backup & Replication is a data management solution used by organizations to handle backups, recovery, and replication for virtual, physical, and cloud-based workloads. It acts as a central control hub for an organization's disaster recovery strategy, ensuring data remains available and consistent across the IT environment. The software includes various background processes, such as the Mount service, which manages how backup data is accessed and presented to the system.

What does CWE-284 mean for CVE-2025-48983?

CWE-284 refers to Improper Access Control. In the context of CVE-2025-48983, this means the Mount service fails to properly restrict or verify the actions that an authenticated user can perform. Because these access checks are insufficient, an attacker who already has valid domain credentials can interact with the service in ways they should not be allowed to, ultimately gaining the ability to execute unauthorized code on the underlying backup infrastructure.

Do I need to be a domain user to trigger this vulnerability?

Yes, successful exploitation requires authenticated domain access. This means an attacker must already have compromised or obtained legitimate credentials within the organization's domain environment to interact with the Mount service. The vulnerability cannot be triggered by an anonymous, unauthenticated user from outside the network, as the service requires existing domain-level authentication to reach the point where the insecure access control can be exploited.

How relevant is this CVE to my internal environment?

According to Halo Surface Signal, this vulnerability is considered unlikely to be directly exposed to the public internet. Veeam Backup & Replication is designed to operate within protected internal management networks. While your servers are likely not public-facing, you should still evaluate the risk based on the potential impact if a compromised internal account were to target the backup infrastructure from within your network perimeter.

How should I begin responding to this threat?

First, identify all instances of Veeam Backup & Replication running versions 12.0.0.1402 through 12.3.2.4164 in your environment. Coordinate with your infrastructure or platform teams to confirm ownership and critical status of these systems. Once identified, prioritize these servers for maintenance cycles to apply the vendor-provided updates, ensuring that backup integrity is maintained during the testing and patching process.

References