---
title: "Security Bulletin: Critical Vulnerability affecting Veeam Backup & Replication"
description: Critical Veeam Backup & Replication vulnerability allows remote code execution by authenticated domain users on domain-joined servers. CVE-2025-23121. CVSS 9.9. Upgrade to 12.3.2.3617 and apply isolation best practices to reduce risk.
---

[Cybersecurity Blog | RedLegg ](https://www.redlegg.com/blog)

# [Security Bulletin: Critical Vulnerability affecting Veeam Backup & Replication](https://www.redlegg.com/blog/security-bulletin-critical-vulnerability-affecting-veeam-06-25)

 Written by [RedLegg's Cyber Threat Intelligence Team](https://www.redlegg.com/blog/author/redleggs-cyber-threat-intelligence-team) | 6/17/25 7:59 PM

About:

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.

## VULNERABILITIES

### Veeam Backup & Replication Domain‑Joined Remote Code Execution Vulnerability

 

**CVSS Score**: 9.9 (Critical)**  
****Identifier**: CVE‑2025‑23121**  
****Exploit or POC**: No  
**Update**: CVE‑2025‑23121 –[ Veeam Security Advisory KB4743](https://www.veeam.com/kb4743)

**Description**: CVE‑2025‑23121 is a critical remote code execution vulnerability affecting Veeam Backup & Replication version 12.x when installed on domain‑joined Windows servers. A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

**Mitigation Recommendation**: Upgrade immediately to Veeam Backup & Replication 12.3.2 (build 12.3.2.3617).

Follow Veeam's security best practices: avoid domain-joining Backup Servers (opt for workgroup or separate AD forest), restrict admin accounts with multifactor authentication, and segment backup environments from production assets.

Note: Due to the critical severity and the nature of systems affected, organizations are strongly urged to implement the fix and review their infrastructure configuration. Taking proactive steps now can help prevent potential exploitation scenarios.*  
*

 

[View full post](https://www.redlegg.com/blog/security-bulletin-critical-vulnerability-affecting-veeam-06-25)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "RedLegg's Cyber Threat Intelligence Team"
  },
  "dateModified" : "2025-06-17T19:59:13.672Z",
  "datePublished" : "2025-06-17T19:59:01Z",
  "headline" : "Emergency Security Bulletin: Veeam Backup & Replication Domain‑Joined Remote Code Execution Vulnerability",
  "image" : {
    "@type" : "ImageObject",
    "height" : 630,
    "url" : "https://www.redlegg.com/hubfs/Emergency%20Bulletin%20v2.png",
    "width" : 1200
  },
  "mainEntityOfPage" : "https://www.redlegg.com/blog/security-bulletin-critical-vulnerability-affecting-veeam-06-25",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/4675768/logo-red-01.png",
      "width" : 419.66666
    },
    "name" : "RedLegg Cybersecurity Blog"
  }
}
```