We would like to inform you of a critical vulnerability that has been patched in the latest update of Veeam Backup and Replication 12.3.0.310. This vulnerability affects all earlier version 12 builds. The issue has been classified as critical-risk, with a CVSSv3 score of 9.9. Given the severity of this vulnerability, it is crucial that you take immediate action to ensure your systems remain secure. Vulnerability Details:
CVE-2025-23120
Description: A vulnerability allowing remote code execution (RCE) by authenticated domain users.
Severity: Critical
CVSS v3.1 Score: 9.9
To secure your environment, we strongly recommend updating to Veeam Backup and Replication 12.3.1 or higher as soon as possible.
See the official communication from Veeam here.