Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Redmi Pad 2 Review: The All-Round Budget Tablet to Get

    HONOR Magic V5 launches in Malaysia for RM6999

    Kingston expands NV3 SSD to M.2 2230 form factor

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Another Chinese AI model is turning heads

      July 15, 2025

      AI chatbot Grok issues apology for antisemitic posts

      July 13, 2025

      Apple sued by shareholders for allegedly overstating AI progress

      June 22, 2025

      How far will AI go to defend its own survival?

      June 2, 2025

      The internet thinks this video from Gaza is AI. Here’s how we proved it isn’t.

      May 30, 2025
    • Business

      Cloudflare open-sources Orange Meets with End-to-End encryption

      June 29, 2025

      Google links massive cloud outage to API management issue

      June 13, 2025

      The EU challenges Google and Cloudflare with its very own DNS resolver that can filter dangerous traffic

      June 11, 2025

      These two Ivanti bugs are allowing hackers to target cloud instances

      May 21, 2025

      How cloud and AI transform and improve customer experiences

      May 10, 2025
    • Crypto

      Bitcoin (BTC) Slides From $123,000 High Ahead of US CPI Print

      July 15, 2025

      Shadowy Entity Behind Trump’s DeFi Project Revealed as Disgraced Web3 Firm

      July 15, 2025

      Satoshi-Era 80,000 BTC Whale Move Coins to CEXs as Bitcoin Hits All-Time Highs

      July 15, 2025

      XRP in Focus as Fed’s ISO 20022 Goes Live – What Traders Should Know

      July 15, 2025

      Bitcoin Skeptic Vanguard Quietly Becomes MicroStrategy’s No. 1 Shareholder

      July 15, 2025
    • Technology

      Best laptops under $500: Affordable picks that will satisfy

      July 15, 2025

      Cyberpunk 2077 comes to Mac… 5 years later

      July 15, 2025

      Logitech’s ultra-compact MX Keys Mini keyboard is 30% off, today only

      July 15, 2025

      Save $440 on the best Samsung and Google phones and 50% on Mint Mobile Unlimited

      July 15, 2025

      Three publishers’ workforce diversity reports show DEI efforts remain sluggish

      July 15, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Shop Now
    Tech AI Verse
    You are at:Home»Technology»New Veeam RCE flaw lets domain users hack backup servers
    Technology

    New Veeam RCE flaw lets domain users hack backup servers

    TechAiVerseBy TechAiVerseJune 18, 2025No Comments2 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    New Veeam RCE flaw lets domain users hack backup servers
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    New Veeam RCE flaw lets domain users hack backup servers

    ​Veeam has released security updates today to fix several Veeam Backup & Replication (VBR) flaws, including a critical remote code execution (RCE) vulnerability.

    Tracked as CVE-2025-23121, this security flaw was reported by security researchers at watchTowr and CodeWhite, and it only impacts domain-joined installations.

    As Veeam explained in a Tuesday security advisory, the vulnerability can be exploited by authenticated domain users in low-complexity attacks to gain code execution remotely on the Backup Server. This flaw affects Veeam Backup & Replication 12 or later, and it was fixed in version 12.3.2.3617, which was released earlier today.

    While CVE-2025-23121 only impacts VBR installations joined to a domain, any domain user can exploit it, making it easy to abuse in those configurations.

    Unfortunately, many companies have joined their backup servers to a Windows domain, ignoring Veeam’s best practices, which advise admins to use a separate Active Directory Forest and protect the administrative accounts with two-factor authentication.

    In March, Veeam patched another RCE vulnerability (CVE-2025-23120) in Veeam’s Backup & Replication software that impacts domain-joined installations.

    Ransomware gangs have also told BleepingComputer years ago that they always target VBR servers because they simplify stealing victims’ data and block restoration efforts by deleting backups before deploying the ransomware payloads on the victims’ networks.

    As Sophos X-Ops incident responders revealed in November, another VBR RCE flaw (CVE-2024-40711) disclosed in September is now being exploited to deploy Frag ransomware.

    The same vulnerability was also used to gain remote code execution on vulnerable Veeam backup servers in Akira and Fog ransomware attacks starting in October.

    In the past, the Cuba ransomware gang and FIN7, a financially motivated threat group known to collaborate with the Conti, REvil, Maze, Egregor, and BlackBasta ransomware gangs, were also observed exploiting VBR vulnerabilities.

    Veeam’s products are used by over 550,000 customers worldwide, including 82% of Fortune 500 companies and 74% of Global 2,000 firms.

    Why IT teams are ditching manual patch management

    Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

    In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleSitecore CMS exploit chain starts with hardcoded ‘b’ password
    Next Article Instagram ‘BMO’ ads use AI deepfakes to scam banking customers
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Best laptops under $500: Affordable picks that will satisfy

    July 15, 2025

    Cyberpunk 2077 comes to Mac… 5 years later

    July 15, 2025

    Logitech’s ultra-compact MX Keys Mini keyboard is 30% off, today only

    July 15, 2025
    Leave A Reply Cancel Reply

    Top Posts

    New Akira ransomware decryptor cracks encryptions keys using GPUs

    March 16, 202528 Views

    OpenAI details ChatGPT-o3, o4-mini, o4-mini-high usage limits

    April 19, 202522 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202522 Views

    Rsync replaced with openrsync on macOS Sequoia

    April 7, 202520 Views
    Don't Miss
    Gadgets July 16, 2025

    Redmi Pad 2 Review: The All-Round Budget Tablet to Get

    Redmi Pad 2 Review: The All-Round Budget Tablet to Get The Redmi Pad series tablets…

    HONOR Magic V5 launches in Malaysia for RM6999

    Kingston expands NV3 SSD to M.2 2230 form factor

    Best laptops under $500: Affordable picks that will satisfy

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Redmi Pad 2 Review: The All-Round Budget Tablet to Get

    July 16, 20252 Views

    HONOR Magic V5 launches in Malaysia for RM6999

    July 16, 20252 Views

    Kingston expands NV3 SSD to M.2 2230 form factor

    July 16, 20251 Views
    Most Popular

    Xiaomi 15 Ultra Officially Launched in China, Malaysia launch to follow after global event

    March 12, 20250 Views

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    French Apex Legends voice cast refuses contracts over “unacceptable” AI clause

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.