After vetting numerous vulnerabilities in the company’s Backup and Replication software via a series of Critical Remote Code Execution (RCE) vulnerabilities (CVE-2025-59470) rated 9 out of 10 by CVSS); Veeam is now issuing security fixes for all of these issues through updates to versions of Backup and Replication 13.x and their predecessors.
This particular vulnerability is found in what is considered two major roles within the software; Backup Operators and Tape Operators, allowing these operators to execute arbitrary system commands on behalf of the Postgres User by injecting a maliciously crafted Interval or Order parameter.
In addition to the aforementioned vulnerability, Veeam is also addressing the following vulnerabilities in the backup and replication software:
1. CVE-2025-55125 (CVSS 7.2) - Arbitrary Code Execution (RCE) as ROOT by creating a malicious backup configuration file
2. CVE-2025-59468 (CVSS 6.7) - RCE as Postgres User by injecting a maliciously created password parameter
3. CVE-2025-59469 (CVSS 7.2) - Writing arbitrary files as ROOT through a Backup Operator or Tape Operator.
These vulnerabilities were discovered in Veeam Backup and Replication version 13.0.1.180 and earlier builds (all 13.X) and they have since been remediated through v13.0.1.1071 updates.
Veeam states that customers mitigate the risk of exploiting a Vulnerability if they follow the security guidelines outlined in the Company. However, prior cases of Cyber Security Incidents have demonstrated that Attackers have previously targeted Backup Software and have reinforced the immediate need to patch.
Recommendations for Cybersecurity for organizations that utilize Veeam Backup and Replication include:
1. Immediately upgraded to V13.0.1.1071
2. Implement Restricted Access to the Backup and Tape Operator Role to Essential Personnel only
3. Audit Backup Transaction Logs and Review for Unusual Backup Job Activity
4. Follow Veeam's Security Recommendations for Privileged Roles.
Source: The Hacker News