Cyber Posture

CVE-2025-48983

Critical

Published: 31 October 2025

Published
31 October 2025
Modified
01 December 2025
KEV Added
Patch
CVSS Score 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0024 46.9th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.

Security Summary

CVE-2025-48983 is a critical vulnerability in the Mount service of Veeam Backup & Replication that allows remote code execution (RCE) on backup infrastructure hosts. Published on 2025-10-31, it carries a CVSS v3.1 base score of 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) and is associated with CWE-284 (Improper Access Control).

The vulnerability can be exploited remotely by an authenticated domain user possessing low privileges. Attackers require network access and minimal setup, with no user interaction needed. Successful exploitation grants RCE on the affected backup hosts, enabling high-impact compromise of confidentiality, integrity, and availability across a changed scope.

Mitigation details are available in the official Veeam knowledge base article at https://www.veeam.com/kb4771.

Details

CWE(s)
NVD-CWE-noinfoCWE-284

Affected Products

veeam
veeam backup \& replication
12.0.0.1402 — 12.3.2.4165

MITRE ATT&CK Enterprise Techniques

T1210 Exploitation of Remote Services Lateral Movement
Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

The vulnerability enables remote code execution (RCE) in the Mount service by low-privileged authenticated domain users, directly facilitating Exploitation of Remote Services (T1210) for lateral movement and Exploitation for Privilege Escalation (T1068) due to the privilege increase and changed scope.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References