← back
CVE-2025-23121criticalCWE-94

CVE-2025-23121

33Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.9epss 18%
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
In short

A Backup Server allows an authenticated domain user to run arbitrary code remotely. This is critical because attackers with valid domain credentials can fully compromise the backup system and access all backed-up data.

Technical detail

CWE-94 (Code Injection) vulnerability in Backup Server permits remote code execution when an authenticated domain user submits specially crafted input. Exploitation requires valid domain credentials and network access; successful exploitation grants arbitrary code execution with server privileges, enabling data exfiltration and system compromise.

Summary generated and translated by AI from the official description.
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H