Tag: Veeam

Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication
News

Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication

In order to fix many vulnerabilities in its Backup & Replication software, including a "critical" problem that might lead to remote code execution (RCE), Veeam has released security upgrades. The vulnerability has a CVSS score of 9.0 and is tagged as CVE-2025-59470. According to a Tuesday notice, this vulnerability enables a Backup or Tape Operator to execute remote code execution (RCE) as the Postgres user by passing a malicious interval or order parameter. A user with a Backup Operator role can start and stop running tasks, export backups, copy backups, and make VeeamZip backups, according to Veeam's documentation. In contrast, a user of Tape Operator has the ability to perform tape backup or catalog tasks, eject tapes, import and export tapes, move tapes to a media pool, copy...
Veeam and IBM Release Patches for High-Risk Flaws in Backup and AIX Systems
News

Veeam and IBM Release Patches for High-Risk Flaws in Backup and AIX Systems

To fix a serious security hole affecting its Backup & Replication software that might result in remote code execution, Veeam has published security upgrades. The vulnerability has a CVSS score of 9.9 out of 10.0 and is tagged as CVE-2025-23120. 12.3.0.310 and all previous builds of version 12 are affected. In a warning published on Wednesday, the company disclosed a vulnerability that permits authorized domain users to execute remote code (RCE). The vulnerability was found and reported by Piotr Bazydlo, a security researcher with watchTowr, and has been fixed in version 12.3.1 (build 12.3.1.1139). Bazydlo and researcher Sina Kheirkhah claim that Veeam's uneven treatment of the deserialization read more about Veeam and IBM Release Patches for High-Risk Flaws in Backup and A...
Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console
News

Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console

To fix a serious vulnerability affecting Service Provider Console (VSPC) that might allow remote code execution on vulnerable instances, Veeam has published security upgrades. Tracked as CVE-2024-42448, the vulnerability has a CVSS score of 9.9 out of 10.0. The problem was discovered during internal testing, according to the company. Veeam stated in an advisory that Remote Code Execution (RCE) on the VSPC server computer is feasible from the VSPC management agent machine, provided that the management agent has server authorization read more about Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions....
Backup Repositories Targeted in 93% of Ransomware Attacks
News

Backup Repositories Targeted in 93% of Ransomware Attacks

According to Veeam's 2023 Ransomware Trends Report, the ransomware threat is still very much present, with 85% of organisations having experienced at least one such assault during the past 12 months. The research forewarns that if this pattern persists, "more organisations will suffer a ransomware attack than turn a profit." Additionally, Veeam discovered that in 93% of ransomware cases, the threat actors target the backup repositories, causing 75% of victims to lose at least some of their backups during the assault and more than 39% of backup repositories to be totally lost read more Backup Repositories Targeted in 93% of Ransomware Attacks. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity trends, and the latest cyberse...