Summary
- CVE-2025-64393 carries a CVSS v4 score of 9.4.
- Exploitation requires a user holding the low privilege Backup Viewer role.
- Version 13 is unaffected, while version 12 users need the P4 update.
Veeam has fixed a critical Backup & Replication vulnerability that can allow a user holding the limited Backup Viewer role to execute code remotely on the Veeam Backup Server.
CVE-2025-64393 affects Veeam Backup & Replication 12.3.2 P3 and older version 12 builds, while version 13 is unaffected. Veeam assigns the weakness a CVSS v4 score of 9.4 and has corrected it in build 12.3.2.4934, released as 12.3.2 P4.
The vulnerability results from insecure deserialisation of untrusted data received through the Mount Service. Exploitation begins from an authenticated position, requiring access to an account holding the Backup Viewer role rather than allowing an unauthenticated user to attack the server directly.
Although that prerequisite reduces exposure, the role itself is designed to be relatively limited. A user allowed to view backup information would not normally be expected to gain the ability to execute arbitrary code on the server responsible for managing backup and recovery operations.
The flaw therefore breaks the boundary intended to keep low privilege access separate from server control. If an attacker has already compromised a Backup Viewer account, the vulnerability can turn that foothold into substantially broader authority inside the backup environment.
That escalation carries particular operational weight because backup platforms influence whether an organisation can recover from destructive attacks. Ransomware groups routinely seek access to backup repositories and management systems after entering a network, attempting to remove or disable recovery options before encrypting production workloads.
Veeam has not said CVE-2025-64393 is being exploited in ransomware attacks or any other active campaign. The relevance comes from the position of the affected server rather than evidence that criminals are already using the flaw.
Backup infrastructure can also maintain connections to hypervisors, repositories, storage systems and protected workloads. Depending on architecture, control of the backup server may therefore expose credentials or trust relationships extending beyond the application itself.
The authenticated prerequisite makes account protection and role separation important alongside patching. An environment that grants Backup Viewer access broadly may face a different practical risk from one in which the role is tightly restricted, even though both run the same vulnerable software.
Veeam’s P4 release fixes several vulnerabilities rather than CVE-2025-64393 alone. The company says all weaknesses covered by KB4934 affect 12.3.2 P3 and older version 12 builds and are resolved in 12.3.2 P4.
Version 12 is scheduled to reach end of support on 28 February 2027, adding a lifecycle decision for organisations that remain on the branch. Applying P4 closes the current vulnerability set, while migration to version 13 places the deployment on a major release that Veeam says is not affected by these flaws.
Where an organisation already suspects unauthorised access to its backup environment, software remediation and incident investigation remain separate activities. Updating prevents future exploitation of the documented weakness, but it cannot determine whether a compromised account previously used the vulnerable path.





