
Veeam warns admins to patch now as critical RCE flaws hit Backup & Replication
Backup vendor Veeam has released security updates to patch multiple vulnerabilities in its widely used Backup and Replication platform, including three critical flaws that could allow authenticated users to execute code on backup servers. Detailed in the company’s advisory KB4830, the vulnerabilities affect Veeam Backup & Replication 12.3.2.4165 and earlier version 12 builds, with fixes now available in build 12.3.2.4465. The disclosure covers five security issues in total, including three remote code execution (RCE) bugs and two high-severity vulnerabilities enabling file manipulation or privilege escalation. Each of the three critical flaws carries a CVSS score of 9.9 out of 10 and allows ...