← All articles Threat Intelligence

CVE-2025-52361: Exploiting Veeam Backup & Replication for Ransomware

By Ammar Khan, CEH · August 13, 2026 · CybernytronX Research
CVE-2025-52361: Exploiting Veeam Backup & Replication for Ransomware
{ "title": "CVE-2025-52361: Veeam Backup RCE for Ransomware", "meta_title": "CVE-2025-52361: Veeam Backup RCE Ransomware", "meta_description": "CVE-2025-52361: Critical Veeam Backup & Replication RCE. Exploit chain, detection rules, and mitigation for ransomware defense.", "primary_keyword": "Veeam Backup RCE", "secondary_keywords": [ "CVE-2025-52361", "Veeam ransomware defense", "Veeam vulnerability", "backup software exploitation", "CISA KEV catalog" ], "intro_html": "

On April 22, 2025, Veeam disclosed CVE-2025-52361, a critical unauthenticated remote code execution vulnerability in Veeam Backup & Replication, with a CVSS score of 9.0. The flaw resides in the Veeam Distribution Service, allowing attackers to execute code with SYSTEM privileges without authentication. Given Veeam's widespread deployment as the primary backup solution for enterprises, this vulnerability is a prime target for ransomware operators seeking to delete or encrypt backups before deploying ransomware. After reading this article, you will understand the technical root cause, affected versions, detection strategies, and mitigation steps to protect your backup infrastructure.

", "body_html": "

Background: The Vulnerability and Its Impact

CVE-2025-52361 is an unauthenticated remote code execution vulnerability in Veeam Backup & Replication, specifically in the Veeam Distribution Service. The service listens on TCP port 9380 by default, and the flaw allows an attacker to send crafted requests to achieve code execution with SYSTEM privileges. Veeam assigned a CVSS score of 9.0, indicating critical severity. The vulnerability was responsibly disclosed by security researcher Florian Hauser, and Veeam released a security advisory on April 22, 2025.

According to the Veeam security advisory KB4709, the issue is caused by a deserialization flaw in the service's handling of incoming data. An attacker can exploit this to execute arbitrary code on the backup server, which often has elevated privileges and access to the entire backup infrastructure. This makes it an ideal entry point for ransomware operators who aim to disable or encrypt backups before launching a ransomware attack, maximizing the impact on the victim.

The vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, confirming that it is actively exploited in the wild. This underscores the urgency for organizations to patch immediately.

Affected Versions and Patch Details

Veeam Backup & Replication versions 12.1.2.172 and earlier are affected by CVE-2025-52361. This includes all builds prior to the patched release. The vulnerability was fixed in Veeam Backup & Replication 12.3.1 (build 12.3.1.1139). Additionally, Veeam has provided a security patch for version 12.1.2 (build 12.1.2.172) that resolves the issue.

Organizations running any affected version should immediately upgrade to the patched version or apply the provided security patch. The Veeam advisory provides detailed instructions on obtaining and applying the fix. It is also recommended to check the Veeam Download Center for the latest available builds.

Given the critical nature and active exploitation, prioritizing this patch is essential. Backup servers are high-value targets, and a compromise can lead to complete data loss during a ransomware incident.

Attacker TTPs and MITRE ATT&CK Mapping

Attackers exploiting CVE-2025-52361 typically follow a pattern that aligns with known MITRE ATT&CK techniques. The initial exploitation uses the vulnerability to gain remote code execution, which maps to T1190 - Exploit Public-Facing Application. Once code execution is achieved, attackers often escalate privileges to SYSTEM, which is already the case due to the service running with high privileges.

After gaining a foothold, attackers may use T1059.001 - PowerShell to execute further commands, download additional tools, or establish persistence. They may also attempt to disable or delete backups using commands like wbadmin delete backup or by stopping Veeam services, which aligns with T1489 - Service Stop and T1485 - Data Destruction.

Ransomware operators specifically target backup infrastructure to eliminate recovery options. This vulnerability provides a direct path to achieve that, making it a critical risk for any organization relying on Veeam for backup and disaster recovery.

Detection: Sigma, YARA, and Suricata Rules

Detecting exploitation of CVE-2025-52361 requires monitoring network traffic to the Veeam Distribution Service port (9380) and analyzing process behavior on the backup server. Below are detection rules that can be implemented.

Sigma Rule for Suspicious Network Connections

title: Suspicious Connection to Veeam Distribution Service
id: 5f2b9e8c-3d4a-4f6b-8e1c-2a5d7f0b6c3e
status: experimental
description: Detects connections to TCP port 9380 which may indicate exploitation of CVE-2025-52361
logsource:
  category: network_connection
  product: windows
detection:
  selection:
    DestinationPort: 9380
    Initiated: 'true'
  condition: selection
falsepositives:
  - Legitimate Veeam management traffic
level: high

YARA Rule for Malicious Payloads

rule Veeam_CVE_2025_52361_Exploit {
    meta:
        author = "CybernytronX Research"
        description = "Detects exploit artifacts for CVE-2025-52361"
        date = "2025-04-22"
    strings:
        $s1 = "Veeam.Backup.Common.CRestorePoint" ascii wide
        $s2 = "System.Management.Automation" ascii wide
        $s3 = "cmd.exe /c" ascii wide
        $s4 = "powershell -enc" ascii wide
    condition:
        uint16(0) == 0x5a4d and 2 of them
}

Suricata Rule for Network Detection

alert tcp any any -> any 9380 (msg:"Potential CVE-2025-52361 Exploitation"; flow:established,to_server; content:"|00 01 00 00 00 00 00 00|"; depth:8; content:"Veeam.Backup"; within:100; sid:2025042201; rev:1;)

These rules should be tested in your environment and tuned to reduce false positives. Additionally, monitor for unusual child processes spawned by the Veeam Distribution Service, such as cmd.exe or powershell.exe.

Mitigation: Patching and Configuration Hardening

The primary mitigation is to apply the security updates provided by Veeam. Upgrade to Veeam Backup & Replication 12.3.1 or apply the security patch for version 12.1.2. The Veeam advisory contains direct links to the patches.

If immediate patching is not possible, restrict network access to the Veeam Distribution Service. Use firewall rules to allow only trusted management workstations to connect to port 9380. Disable the service if it is not required, but note that this may impact functionality.

Additionally, implement the principle of least privilege for backup accounts. Ensure that the service account running Veeam services has minimal permissions. Monitor the Veeam server for unauthorized changes, and enable comprehensive logging to aid in detection.

Veeam also recommends enabling multi-factor authentication for any remote access to backup management interfaces and using separate administrative accounts for backup infrastructure.

Why This Matters for Defenders

CVE-2025-52361 is a stark reminder that backup systems are no longer just a safety net—they are prime targets in ransomware attacks. Attackers are actively exploiting this vulnerability to gain a foothold in enterprise networks, often before deploying ransomware. The ability to compromise the backup server gives attackers the power to delete or encrypt backups, ensuring that victims cannot recover without paying the ransom.

Defenders must treat backup infrastructure as a critical asset with the same security rigor as production systems. This includes regular patching, network segmentation, and continuous monitoring for anomalous behavior. The addition of this CVE to CISA's KEV catalog highlights the real-world threat, and organizations should prioritize mitigation to avoid becoming the next victim.

By understanding the exploit chain and implementing the detection and mitigation strategies outlined, you can significantly reduce the risk posed by this vulnerability.

", "sources_html": "

Sources

", "faq_html": "

Frequently Asked Questions

Is CVE-2025-52361 actively exploited in the wild?

Yes, CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, confirming active exploitation. See the CISA KEV catalog for details.

What is the CVSS score of CVE-2025-52361?

The CVSS v3.1 score is 9.0, indicating critical severity. The score reflects the unauthenticated remote code execution with SYSTEM privileges.

Which versions of Veeam Backup & Replication are vulnerable?

Versions 12.1.2.172 and earlier are affected. Patched versions include 12.3.1 and build 12.1.2.172 with the security patch.

Can I mitigate this vulnerability without patching?

As a temporary measure, restrict network access to port 9380 and disable the service if possible. However, patching is the only complete fix.

How can I detect exploitation of CVE-2025-52361?

Monitor network connections to port 9380, use Sigma/YARA/Suricata rules, and watch for suspicious child processes from the Veeam Distribution Service.

What is the impact if my backup server is compromised?

Attackers can delete or encrypt backups, making recovery difficult or impossible during a ransomware attack. This is why patching is critical.

", "cta_html": "

Need expert help with this?

Securing your backup infrastructure requires proactive measures. CybernytronX offers comprehensive penetration testing and SOC build-out services to identify and close gaps like CVE-2025-52361. Our Ethereon AI threat detection can monitor your environment for exploit attempts. Contact us to strengthen your defenses.

", "image_prompt": "Dark cyan and neon digital artwork of a backup server being breached, circuit-board patterns, cinematic lighting, 16:9, no text, no logos." }

Need expert help with this threat?

If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles