Advisory Details

July 21st, 2025

Veeam Backup Enterprise Manager JobManagmentService Improper Access Control Remote Code Execution Vulnerability

ZDI-25-625
ZDI-CAN-26062

CVE ID CVE-2025-24286
CVSS SCORE 6.8, AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AFFECTED VENDORS Veeam
AFFECTED PRODUCTS Backup Enterprise Manager
VULNERABILITY DETAILS

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Veeam Backup Enterprise Manager. Authentication is required to exploit this vulnerability.

The specific flaw exists within the JobManagmentService component. The issue results from improper access control. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.

ADDITIONAL DETAILS Veeam has issued an update to correct this vulnerability. More details can be found at:
https://www.veeam.com/kb4743
DISCLOSURE TIMELINE
  • 2025-03-10 - Vulnerability reported to vendor
  • 2025-07-21 - Coordinated public release of advisory
  • 2025-07-21 - Advisory Updated
CREDIT Nikolai Skliarenko of Trend Micro Security Research
BACK TO ADVISORIES