Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Trump’s Oil’s preferred price is $40-50 based on his social media post

Xinbi Telegram Market is $840 million in crypto crime, romance fraud, North Korean laundry

As combat resumes in Tripoli, Libya, we are seeking calmness | Conflict News

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Veeam and IBM release patches for high-risk defects in backup and AIX systems
Identity

Veeam and IBM release patches for high-risk defects in backup and AIX systems

userBy userMarch 20, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 20, 2025Ravi LakshmananVulnerabilities/Software Updates

Veeam and IBM

Veeam has released a security update to address critical security flaws affecting backup and replication software that could lead to remote code execution.

The vulnerability tracked as CVE-2025-23120 has a CVSS score of 9.9 out of 10.0. Affects 12.3.0.310 and all previous version 12 builds.

“The vulnerability allows remote code execution (RCE) by authenticated domain users,” the company said in an advisory released Wednesday.

Watchtowr security researcher Piotr Bazydlo is acknowledged to have discovered and reported defects resolved in version 12.3.1 (build 12.3.1.1139).

According to Bazydlo and researcher Sina Kheirkhah, CVE-2025-23120 stems from the inconsistent handling of Veeam’s deintervention mechanism, causing a class that could be escaped.

This also means that threat actors can leverage blocklists, i.e. veeam.backup.esxmanager.xmlframeworks and veeam.backup.core.backupsummary – to achieve remote code execution.

Cybersecurity

“These vulnerabilities could be exploited by users who belong to a local user group on the Windows host of a Veeam server,” the researchers said. “Even better – if you combine servers into a domain, these vulnerabilities could be exploited by any domain user.”

The patch introduced by Veeam adds two gadgets to an existing block list. This means that if other viable detrimental backward gadgets are discovered, the solution could once again be vulnerable to similar risks.

This development occurs because IBM has issued a fix to fix two important bugs in the AIX operating system that allows the command to be executed.

The list of drawbacks affecting AIX versions 7.2 and 7.3 is

CVE-2024-56346 (CVSS score: 10.0) – Inappropriate access control vulnerability that allows remote attackers to execute arbitrary commands via AIX Nimsis NIM Master Service CVE-2024-56347 (CVSS score: 9.6) SSL/TLS protection mechanism

Although there is no evidence that any of these serious defects are being exploited in the wild, users are advised to move quickly to apply the necessary patches to combat potential threats.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEthiopia eliminates conflict with Eritrea via Red Sea access | Conflict News
Next Article The claim against the founder of Be Club is the founder of the club on withdrawn Onecoin
user
  • Website

Related Posts

Xinbi Telegram Market is $840 million in crypto crime, romance fraud, North Korean laundry

May 14, 2025

CTM360 Identifies a surge in phishing attacks targeting metabusiness users

May 14, 2025

Drone supply chain violated Art Amit via ERP in Tidrone campaign

May 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Trump’s Oil’s preferred price is $40-50 based on his social media post

Xinbi Telegram Market is $840 million in crypto crime, romance fraud, North Korean laundry

As combat resumes in Tripoli, Libya, we are seeking calmness | Conflict News

Max has been renamed HBO Max and no one wants to fix the name change

Trending Posts

As combat resumes in Tripoli, Libya, we are seeking calmness | Conflict News

May 14, 2025

Israeli attack on Gaza kills 70 when ceasefire talk continues | Israeli-Palestinian conflict news

May 14, 2025

Former Olympic cyclist Rohan Dennis has been suspended over his wife’s death | Cycling News

May 14, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

AI infrastructure startup TensorWave raises $100 million to meet the rising demand for AI calculations

DataBricks acquires serverless database startup neon for $1 billion to boost AI agent development

All the steps you can take to make your online bet safer

Etoro is revealed at a $52 IPO and is worth $4.2 billion amid the retail and crypto boom

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.