![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxnk_lJPUS0BZwNO2mx9Vb4ppUN3ifSvJyWHtZEsMV-IeDiE3SlnZ9ZXTwkifc8es3msSjnCBpd2Qk2dVP3g5LrEld-diDiVvaLmwQvzeU9XmuJ_4ecSUIma-aq_AVts43QUj_6mG7VQiNMZEAe8pdkAL2vGl7gQWILWF0BerXRGAFv1Y1WfwlgDsideeS/s728-rw-e365/veeam.jpg)
VEEAM has released patches that deal with important security defects that affect the backup software that allows the attacker to run any code in the sensitivity system.
The vulnerability tracked as CVE-2025-23114 is equipped with a 9.0 CVSS score out of 10.0.
VEEAM stated in the advisory, “VEEAM UPDATER components that allow the attacker to use the intermediate attack to be able to run any code on an appliance server influenced by root -level authority.” 。
The drawbacks will affect the following products-
Salesforce’s VEEAM backup -Nutanix AHV 3.1 and old VEEAM backup -5.0 | 5.1 (not affected by defects after version 6) VEEAM BACKUP -6A | 7 (Version 8 is not affected by defects) Microsoft Azure VEEAM BACKUP -5A | 6 (Version 7 is not affected by defect) Red Hat Virtualization VEEAM backup –3 | 4.0 | 4.1 (after version 5 is not affected by defects)
![Cyber security](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhT2OnXk97z-adL5WBKzz6wsA7vAhygg3Px0VPmqpH5hH4AErnYajTCpDN7SLy43ejD_T4Skv8OMOdG9qpzMfihrj8o7qSznLKA8zg7jW8L4hY8-umwTNZSpAj0JvtG3VGMFGw9n7hMyea1NpVSXp6yTaClLUQ3GujxwlEuLmQFSsVH28WQy6vp-cOGG0p_/s728-rw-e100/saas-security-v2-d.png)
It is handled in the following version-
Salesforce VEEAM BACKUP -VEEAM Updater Component version 7.9.0.1124 Nutanix AHV VEEAM BACKUP -VEEAM Updater Component version 9.0.0.1125 AWS for AWS Updater Component version 9.0.0.1126 MICEAM Updater Component version 9.0.0.1128 VEEAM BACKUP Google Cloud VEEAM BACKUP- VEEAM UPDATER component version 9.0.0.1128 Oracle Linux virtualization manager and Red Hat Veeam Backup -veeam Updater Component version 9.0.0.1127
“VEEAM backup and replication development is not affected by vulnerability if the AWS, Google Cloud, Microsoft Azure, Nutanix AHV, or Oracle Linux VM/RED HAT virtualization is not protected.” The company states.
Source link