Trending

ee-track">
Link copied!

Man-in-the-Middle Attack Risk: Veeam Urges Urgent Patching for CVE-2025-23114

A critical vulnerability (CVE-2025-23114) in Veeam Updater allows remote code execution via MitM attacks. Users must apply patches immediately to prevent exploitation.

February 10, 2025 · 3 min read
Man-in-the-Middle Attack Risk: Veeam Urges Urgent Patching for CVE-2025-23114

Overview

Veeam has issued a security update to address a critical vulnerability (CVE-2025-23114) affecting its Veeam Updater component. This flaw allows attackers to execute arbitrary code remotely by leveraging a Man-in-the-Middle (MitM) attack. The vulnerability has a CVSS v3.1 score of 9.0, indicating a severe security risk. Users and administrators of affected products should update their software immediately to mitigate potential threats.

Technical Details

The vulnerability exists due to improper Transport Layer Security (TLS) certificate validation in the Veeam Updater component. Attackers can intercept and modify communication between the Veeam Backup server and update sources, enabling them to execute arbitrary code with root privileges. Given the high severity of this flaw, exploitation could lead to complete system compromise, data loss, or ransomware attacks.

Affected Products

The following Veeam Backup products contain the vulnerable Veeam Updater component:

Current Releases:

  • Veeam Backup for Salesforce – Version 3.1 and older

Previous Releases:

  • Veeam Backup for Nutanix AHV – Versions 5.0 and 5.1 (Fixed in v6 released on August 24, 2024)
  • Veeam Backup for AWS – Versions 6a and 7 (Fixed in v8 released on July 2, 2024)
  • Veeam Backup for Microsoft Azure – Versions 5a and 6 (Fixed in v7, released on July 2, 2024)
  • Veeam Backup for Google Cloud – Versions 4 and 5 (Fixed in v6, released on December 3, 2024)
  • Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization – Versions 3, 4.0, and 4.1 (Fixed in v5, released on August 24, 2024)

Mitigation and Patching

Veeam strongly advises users to update their systems immediately.

  • For Veeam Backup for Salesforce, an additional update is required to secure the current version.
  • Users of other affected products should ensure they are running the latest patched versions listed above.
  • Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization users must update the appliance through the Veeam Backup & Replication Console.

Security Implications

The CVE-2025-23114 vulnerability is particularly concerning because it allows attackers to gain root access to affected servers. This level of access enables:

  • Data exfiltration – Attackers can steal sensitive backup data.
  • Ransomware deploymentMalicious actors can encrypt data and demand payment for its release.
  • Lateral movement – Attackers can pivot within a compromised network to target additional systems.

Previous Veeam Vulnerabilities

This is not the first critical security flaw discovered in Veeam’s backup solutions:

report-ad-banner
  • CVE-2024-40711 – A remote code execution (RCE) vulnerability in Veeam Backup & Replication with a CVSS score of 9.8 was actively exploited by ransomware groups like Fog and Akira.
  • VSPC RCE Vulnerability – In December 2024, Veeam patched another critical RCE flaw in its Veeam Service Provider Console (VSPC).

Conclusion

The discovery of CVE-2025-23114 reminds us how critical it is to stay ahead of security threats. Organizations using Veeam backup solutions should waste no time in applying patches and verifying update authenticity to block potential MitM attacks. However, patching alone isn’t enough—security teams must also evaluate network defenses, strengthen endpoint security, and implement monitoring tools to catch suspicious activity early. Staying vigilant and taking a layered approach to security will help organizations reduce their exposure to cyber threats and keep their systems safe.

References:

AI Threat Intelligence

Stop Executive Threats
Before They Strike

Monitor dark web chatter, detect lookalike domains, and protect your C-suite from targeted impersonation — in real time, across 50+ countries.

Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams