AI description
CVE-2025-64393 is a vulnerability in Veeam Backup & Replication that stems from the insecure deserialization of untrusted data processed through the Mount Service. This flaw allows an authenticated, low-privileged user assigned the Backup Viewer role to execute arbitrary code on the Veeam Backup Server. By sending a crafted serialized object to the server, an attacker can trigger remote code execution (RCE) within the context of the Veeam service account. The vulnerability affects Veeam Backup & Replication version 12.3.2 P3 (build 12.3.2.4854) and older builds, while version 13 builds are unaffected. Veeam addressed the issue in the release of version 12.3.2 P4 (build 12.3.2.4934). The flaw was reported to Veeam through HackerOne, and at the time of its public disclosure, there were no reports of active exploitation in the wild or public proof-of-concept exploits.
- Description
- This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.
- Source
- support@hackerone.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 9.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- support@hackerone.com
- CWE-502
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
5
Veeam Backup & Replicationのv12に、閲覧専用のBackup ViewerロールからバックアップサーバーのSYSTEM権限を奪える脆弱性(CVE-2025-64393、CVSS 9.4)が見つかった。 https://t.co/yElEWZg6rI 管理者権限が無事でも、閲覧用アカウ
@joho_no_todai
10 Oct 2026
948 Impressions
0 Retweets
9 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical Veeam Backup & Replication Flaw (CVE-2025-64393) Lets Backup Viewer Role Execute Code as SYSTEM Critical Vulnerability Alert! Veeam Backup & Replication 12 through 12.3.2.4854 is affected by CVE-2025-64393. 🔍 Identify Targets via ZoomEye: Search Dork:
@zoomeyebot
9 Oct 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Veeam Backup & Replicationに重大な脆弱性―CVE-2025-64393など4件を修正 https://t.co/pKKT5vdffV #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
@securityLab_jp
9 Oct 2026
502 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
バックアップ担当には「閲覧だけ」の権限が怖い話だ。 Veeam Backup & Replicationの修正情報が挙げるCVE-2025-64393は、認証済みのBackup Viewer権限からバックアップサーバーでRCEが可能になる脆弱性。CVSSは9.4。閲覧
@connect24h
8 Oct 2026
848 Impressions
0 Retweets
3 Likes
2 Bookmarks
0 Replies
0 Quotes
#schwachstellen CVE-2025-64393: Kritische Lücke in Veeam Backup & Replication ermöglicht Codeausführung als SYSTEM #cve202564393 #veeam #veeambackupreplication https://t.co/zwVP5zEZ9u
@cybsecuritynews
8 Oct 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Veeam Backup & Replication 12に重大なRCE脆弱性CVE-2025-64393(CVSS 9.4) — 12.3.2 P4で3件を修正、バージョン13は影響なし https://t.co/VaFEunWsLg
@NEXSIGHTNEWS
8 Oct 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
『allowing a low-privileged user with the Backup Viewer role to perform remote code execution (RCE) on the Veeam Backup Server』 CVE-2025-64393 KB4934: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 https://t.co/TM7QVXfNDp
@autumn_good_35
7 Oct 2026
786 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
Warning: A critical remote code execution vulnerability in #Veeam Backup & Replication allows a low-privileged user with the Backup Viewer role to execute code on the Backup Server. #CVE-2025-64393 CVSS(4.0): 9.4. Read more: https://t.co/00zGLyY04R and #Patch #Patch #Patch
@CCBalert
7 Oct 2026
244 Impressions
3 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Veeam patches a critical Backup & Replication flaw that allows code execution as SYSTEM CVE-2025-64393 A critical vulnerability (CVE-2025-64393, CVSS 9.4) lets a user with the read-only Backup Viewer role run arbitrary code… #CVE #Veeam #infosec https://t.co/yVkhId
@Orbitaley
7 Oct 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Big security alert: Veeam Backup & Replication just fixed a remote code execution flaw (CVE-2025-64393) plus XSS, arbitrary file read, and credential exposure—CVSS up to 9.4. If you're on version 12 (build ≤ 12.3.2.4854) or certain 13 builds, update to 12.3.2.4934 now. ht
@dailytechonx
7 Oct 2026
52 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Veeam Backup & Replication Vulnerability: Critical RCE Flaw CVE-2025-64393 (Veeam Backup & Replicationに重大なRCE脆弱性、低権限ユーザーからバックアップサーバー侵害の恐れ) #SecurityOnline (Oct 7) https://t.co/qyvk2CxwVu
@foxbook
7 Oct 2026
257 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical Veeam Backup vulnerability CVE-2025-64393 (CVSS 9.4) enables RCE by low-privileged users. Update to 12.3.2 P4 now. #Veeam #VeeamBackup #CVE202564393 #RCE #Deserialization #Ransomware #BackupSecurity #Vulnerability https://t.co/gI6HTczEHn
@Daily_CyberSec
6 Oct 2026
1218 Impressions
5 Retweets
25 Likes
4 Bookmarks
1 Reply
0 Quotes