External risk intelligence

Veeam Backup & Replication SYSTEM Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2025-64393

Veeam Backup & Replication servers are typically deployed within internal data centers or private management networks. While they are network-accessible within an organization, they are not intended for direct exposure to the public internet, and such deployment would be considered an unusual configuration.

Deserialization

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Veeam Backup & Replication could allow unauthorized users to execute code with system-level privileges on backup servers. This could potentially impact the integrity and availability of backup data. The main concern is confirming relevance and exposure.

  • Compromised backup viewer access allows remote code execution.
  • Protects integrity and availability of critical backup data.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with Backup Viewer privileges can exploit this vulnerability to achieve code execution as the SYSTEM user on the backup server. This typically involves an attacker starting from a position of limited access within the network, then leveraging their Backup Viewer role to interact with a vulnerable component in Veeam Backup & Replication. Successful exploitation could allow the attacker to take full control of the backup server.

  • Requires Backup Viewer access.
  • Triggers by interacting with the vulnerable component.
  • Risk of SYSTEM code execution on the server.

Live Threat

Current exploitation, exposure, and threat context

A Backup Viewer in Veeam Backup & Replication could execute arbitrary code with SYSTEM privileges on the backup server, when supported by the advisory. This means an authenticated user with the Backup Viewer role could potentially compromise the entire backup server.

  • Backup server system
  • Unauthenticated code execution as SYSTEM
  • Complete backup data compromise

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Veeam Backup & Replication necessitates immediate action to identify and secure affected backup servers. Given the nature of backup infrastructure, ownership is likely shared between the infrastructure or platform teams responsible for the server environment and the application owners who manage the Veeam software. The first practical step is to confirm the deployment locations of Veeam Backup & Replication, assess their network reachability, and determine their business criticality to prioritize remediation efforts.

  • Owner: Infrastructure/Platform teams and application owners.
  • Verify: Backup server network exposure and criticality.
  • Action: Plan and coordinate remediation activities.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Veeam Backup & Replication used for?

Veeam Backup & Replication is enterprise-grade software designed to manage, protect, and recover virtual, physical, and cloud-based workloads. Organizations use it to centralize data protection, ensuring that critical information can be restored if primary systems fail. It serves as a foundational component for business continuity and disaster recovery by maintaining secure copies of data across complex IT environments.

What does CWE-502 mean for CVE-2025-64393?

CVE-2025-64393 involves CWE-502, which is the Deserialization of Untrusted Data. In plain terms, this means the software improperly processes data received from a user, allowing the system to interpret malicious input as legitimate commands. Because this vulnerability grants SYSTEM-level access, an attacker can bypass normal restrictions to execute arbitrary code, effectively taking full control of the backup server's underlying operating system.

How is this Veeam vulnerability triggered?

The vulnerability is triggered when an attacker who already possesses Backup Viewer privileges interacts with a specific, vulnerable component in the software. It is important to note that this is not a general unauthenticated attack; it requires an account with existing, limited access within the Veeam environment. Without the necessary Backup Viewer credentials, an attacker cannot initiate the sequence required to execute code as the SYSTEM user.

Is my server at risk based on Halo Surface Signal?

According to Halo Surface Signal, these servers are typically found inside private management networks or internal data centers rather than directly on the public internet. While an internal network presence does not eliminate risk, the likelihood of outside, internet-based exploitation is considered low. You should care if your backup servers are reachable from segments of your network where compromised user credentials might exist.

What should I do to address this vulnerability?

Your first step is to identify all instances of Veeam Backup & Replication within your infrastructure. Coordinate with both the infrastructure teams that manage the servers and the application owners who handle the software to assess where these assets reside. Once identified, evaluate their network connectivity and overall business criticality to prioritize your security planning and remediation efforts.

References