A vulnerability allowing remote code execution (RCE) for domain users.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://www.veeam.com/kb4724 | vendor advisory |
https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/ | exploit third party advisory |