Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Beneficiaries of AI-driven nuclear construction can collect 50%, according to Evercore ISI

AI infrastructure startup TensorWave raises $100 million to meet the rising demand for AI calculations

Buy Databricks Open-Source Database Startup Neon for $1 billion

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Veeam and IBM release patches for high-risk defects in backup and AIX systems
Identity

Veeam and IBM release patches for high-risk defects in backup and AIX systems

userBy userMarch 20, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 20, 2025Ravi LakshmananVulnerabilities/Software Updates

Veeam and IBM

Veeam has released a security update to address critical security flaws affecting backup and replication software that could lead to remote code execution.

The vulnerability tracked as CVE-2025-23120 has a CVSS score of 9.9 out of 10.0. Affects 12.3.0.310 and all previous version 12 builds.

“The vulnerability allows remote code execution (RCE) by authenticated domain users,” the company said in an advisory released Wednesday.

Watchtowr security researcher Piotr Bazydlo is acknowledged to have discovered and reported defects resolved in version 12.3.1 (build 12.3.1.1139).

According to Bazydlo and researcher Sina Kheirkhah, CVE-2025-23120 stems from the inconsistent handling of Veeam’s deintervention mechanism, causing a class that could be escaped.

This also means that threat actors can leverage blocklists, i.e. veeam.backup.esxmanager.xmlframeworks and veeam.backup.core.backupsummary – to achieve remote code execution.

Cybersecurity

“These vulnerabilities could be exploited by users who belong to a local user group on the Windows host of a Veeam server,” the researchers said. “Even better – if you combine servers into a domain, these vulnerabilities could be exploited by any domain user.”

The patch introduced by Veeam adds two gadgets to an existing block list. This means that if other viable detrimental backward gadgets are discovered, the solution could once again be vulnerable to similar risks.

This development occurs because IBM has issued a fix to fix two important bugs in the AIX operating system that allows the command to be executed.

The list of drawbacks affecting AIX versions 7.2 and 7.3 is

CVE-2024-56346 (CVSS score: 10.0) – Inappropriate access control vulnerability that allows remote attackers to execute arbitrary commands via AIX Nimsis NIM Master Service CVE-2024-56347 (CVSS score: 9.6) SSL/TLS protection mechanism

Although there is no evidence that any of these serious defects are being exploited in the wild, users are advised to move quickly to apply the necessary patches to combat potential threats.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEthiopia eliminates conflict with Eritrea via Red Sea access | Conflict News
Next Article The claim against the founder of Be Club is the founder of the club on withdrawn Onecoin
user
  • Website

Related Posts

Drone supply chain violated Art Amit via ERP in Tidrone campaign

May 14, 2025

Horabot Malware targets six Latin American countries using invoice-themed phishing emails

May 14, 2025

Why offensive security training benefits the entire security team

May 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Beneficiaries of AI-driven nuclear construction can collect 50%, according to Evercore ISI

AI infrastructure startup TensorWave raises $100 million to meet the rising demand for AI calculations

Buy Databricks Open-Source Database Startup Neon for $1 billion

Drone supply chain violated Art Amit via ERP in Tidrone campaign

Trending Posts

Israeli attack on Gaza kills 70 when ceasefire talk continues | Israeli-Palestinian conflict news

May 14, 2025

Former Olympic cyclist Rohan Dennis has been suspended over his wife’s death | Cycling News

May 14, 2025

Trump meets Syrian Alshara and normalizes his bond with Damascus | Donald Trump News

May 14, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

AI infrastructure startup TensorWave raises $100 million to meet the rising demand for AI calculations

INE Security Alerts: Continuous CVE Practices Close the Important Gap Between Vulnerability Alerts and Effective Defense

Hot Labs secures $250,000 grant from the Stellar Foundation to accelerate innovation in chain abstraction

BC.Game announces new logos to enhance crypto integration for Igameing Ecosystem

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.