Veeam patches a critical Backup & Replication flaw that allows code execution as SYSTEM
A critical vulnerability (CVE-2025-64393, CVSS 9.4) lets a user with the read-only Backup Viewer role run arbitrary code with SYSTEM privileges on the backup server. Veeam has fixed it in Backup & Replication 12.3.2 P4.
What happened
On 6 October 2026 Veeam published advisory KB4934, which resolves a critical vulnerability in Veeam Backup & Replication tracked as CVE-2025-64393. The flaw carries a CVSS score of 9.4 out of 10 (critical).
According to the published description, the issue allows a user holding the Backup Viewer role — a low-privileged, read-oriented profile — to execute arbitrary code with SYSTEM permissions on the backup server. In practice, a simple viewing account can end up taking full control of the backup infrastructure, which is exactly the last line of defence during a ransomware incident.
Who is affected
Veeam's advisory sets out the scope clearly:
- Affected: all Veeam Backup & Replication builds up to and including 12.3.2 P3 (build 12.3.2.4854), covering the 12, 12.1, 12.2, 12.3, 12.3.1 and 12.3.2 branches.
- Fixed: Veeam Backup & Replication 12.3.2 P4 (build 12.3.2.4934).
- Not affected: any Veeam Backup & Replication version 13 build.
Exploitation status
There is no confirmed active exploitation at this time: the vulnerability is not listed in CISA's KEV catalogue and no public exploit code is known. FIRST has not yet assigned an EPSS score, so there is no published estimate of exploitation likelihood.
That should not be read as a reason to delay. Veeam itself notes in the advisory that once a vulnerability and its patch are disclosed, attackers commonly reverse-engineer the fix to target deployments that have not been updated. Backup servers are also a priority target in ransomware operations.
What to do
We recommend acting within days rather than waiting for the usual maintenance window, particularly if the server is network-exposed or if external users hold roles in the console.
- Upgrade Veeam Backup & Replication to version 12.3.2 P4 (build 12.3.2.4934), or move to version 13, which is not affected.
- Check the installed build: anything at 12.3.2.4854 or older is vulnerable.
- Review who holds the Backup Viewer role and remove it from accounts that do not need it, applying least-privilege principles.
- Restrict network access to the Veeam console and server so it is reachable only from trusted administrative networks.
- Review access and activity logs on the backup server for unusual use of low-privileged accounts.
- Plan the migration away from version 12: Veeam notes that it reaches End of Support on 28 February 2027.
Context
The vendor advisory does not describe any temporary or alternative mitigation: the stated remedy is installing the P4 patch. Veeam also reports no known incidents linked to this flaw.
If your organisation relies on Veeam as the backbone of its recovery strategy, this server deserves the same criticality rating as a domain controller, both in patching cadence and in access control.
Sources
Affected technologies
Vulnerabilities (1)
| CVE | Severity | Active exploitation | Published | NVD status |
|---|---|---|---|---|
| CVE-2025-64393 | Critical (9.4) | — | 10/7/2026 | Received |
Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.