CVE-2025-23120

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 20, 2025
Updated: Apr 2, 2025
CWE ID 502

Summary

CVE-2025-23120 is a newly disclosed vulnerability that poses a serious threat, allowing remote code execution (RCE) for domain users. This issue grants attackers the ability to run arbitrary code on affected systems from a remote location, potentially leading to unauthorized system access, data theft, or further exploitation. The exact cause of the vulnerability has not been disclosed, but it is recommended that affected organizations apply the necessary patches as soon as possible to mitigate the risk. Failure to address this vulnerability could result in significant damage to an organization's security posture.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Veeam Backup & Replication

Affected Vendors

  • Veeam