External risk intelligence

Backup Operator RCE in Veeam Backup & Replication due to malicious parameter

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2025-59470

Veeam Backup & Replication is primarily deployed within internal, protected network segments to manage data backups. While the application is network-accessible, it is not designed to be directly exposed to the public internet, and such exposure would be considered an unusual and insecure configuration.

Remote Code Execution

Veeam Backup \& Replication

13.0.0.4967 to before 13.0.1.1071

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Veeam Backup & Replication could allow a malicious actor with privileged access to execute arbitrary code on your systems. This means they could potentially take control of backup operations, impacting data integrity and availability. Understanding the nature of this threat is key to assessing our security posture.

  • A privileged user can execute malicious code.
  • Affects data backup and recovery integrity.
  • Confirm relevance and assess exposure risk.

Attack Path

How an attacker could exploit the issue

An attacker with Backup Operator privileges could send specially crafted requests to the Veeam Backup & Replication server. These requests, containing malicious values in the "interval" or "order" parameters, could then be used to execute arbitrary code on the server with the privileges of the postgres user.

  • Requires Backup Operator access.
  • Sends malicious interval or order parameter.
  • Leads to remote code execution.

Live Threat

Current exploitation, exposure, and threat context

A Backup Operator could execute arbitrary code on the system as the postgres user by sending specially crafted interval or order parameters to the vulnerable application. This could impact system integrity and data confidentiality when the application is accessed by an authenticated Backup Operator.

  • System access and control.
  • Malicious parameters sent to the application.
  • Remote code execution as postgres user.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Veeam Backup & Replication, and ownership likely resides with the Backup Administrators and the Infrastructure or Platform teams responsible for its deployment and management. The first practical step is to identify all instances of the affected Veeam product, confirm their network exposure and business criticality, and then coordinate remediation with the relevant system owners, potentially involving vendor engagement for updates or patches.

  • Backup and Infrastructure teams own.
  • Verify affected Veeam instances.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Veeam Backup & Replication?

Veeam Backup & Replication is enterprise software used to manage data protection, backups, and recovery across virtual, physical, and cloud environments. It serves as a central hub for securing critical business data, often integrating with database services like PostgreSQL to track operations and maintain system state.

What does CWE-77 mean for CVE-2025-59470?

CWE-77 refers to Command Injection. In this CVE, it means the software fails to properly sanitize specific input parameters before passing them to a system shell. By injecting malicious commands into the interval or order fields, an attacker can trick the application into executing unauthorized code directly on the underlying operating system.

How can an attacker trigger this vulnerability?

An attacker must already have authenticated access as a Backup Operator to send the crafted requests. Simply having network access is insufficient; the attack relies on the ability to interact with specific internal API functions using malicious parameter values. It does not trigger from unauthenticated requests or standard read-only monitoring activities.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal indicates that risk is currently unlikely for most environments because Veeam Backup & Replication is designed to function within internal, protected network segments. If your instance is not directly exposed to the public internet, you are following standard deployment patterns that isolate the application from external attackers.

What steps should I take if I use this software?

First, identify all installed versions of Veeam Backup & Replication in your environment to see if they fall within the 13.0.0.4967 to 13.0.1.1071 range. Verify your current network configuration to ensure the application is restricted from internet access. Finally, coordinate with your infrastructure team to apply the vendor's provided updates.

References