CVE-2025-23120 | Veeam Backup and Recovery 12.0/12.1/12.2/12.3 Domain User deserialization (kb4724 / Nessus ID 232985)
A vulnerability, which was classified as very critical, was found in Veeam Backup and Recovery 12.0/12.1/12.2/12.3. Affected is an unknown function of the component Domain User Handler. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2025-23120. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.