CVE-2025-55125
7.8Veeam · Backup And Recovery
A vulnerability in Veeam Backup and Recovery allows an authenticated Backup or Tape Operator to execute arbitrary code as root via a crafted backup configuration file.
Executive summary
A critical vulnerability in Veeam Backup and Recovery enables authenticated operators to achieve remote code execution as root, posing a severe risk to backup infrastructure integrity.
Vulnerability
This flaw involves an improper handling of backup configuration files that allows an authenticated user with Backup or Tape Operator privileges to escalate their permissions to root. The vulnerability effectively turns a legitimate administrative function into a vector for full system compromise.
Business impact
The ability for an operator to achieve root-level code execution represents a total compromise of the backup server. Given the CVSS score of 7.8, this vulnerability poses a significant risk to data integrity and business continuity, as attackers could modify, delete, or exfiltrate sensitive backup data.
Remediation
Immediate Action: Review the official vendor advisory at https://www.veeam.com/kb4792 and apply all recommended security updates or configuration workarounds provided by Veeam.
Proactive Monitoring: Monitor system logs for unauthorized modifications to backup configuration files and unusual process execution patterns originating from the Backup or Tape Operator accounts.
Compensating Controls: Restrict administrative access to the backup server to a minimal set of trusted personnel and implement strict least-privilege policies to ensure only necessary users hold operator roles.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
This vulnerability is highly severe because it allows for a complete takeover of the backup environment by an existing user. Organizations utilizing Veeam Backup and Recovery version 13.0.0 must prioritize the application of vendor-supplied patches or security guidance immediately to prevent potential unauthorized root access and data manipulation.