# CVE-2025-64393: Critical Veeam Backup & Replication RCE via Mount Service Insecure Deserialization

> Insecure deserialization of untrusted data received via the Veeam Backup & Replication Mount Service lets a low-privileged authenticated user holding the Backup Viewer role execute arbitrary code (as SYSTEM per NVD) on the Veeam Backup Server. Affects version 12 builds up to and including 12.3.2.4854; fixed in 12.3.2 P4 (build 12.3.2.4934). Version 13 is not affected.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3191
- **ID:** TL-2026-3191
- **Severity:** CRITICAL (CVSS 9.4)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 7 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-64393

## Description

CVE-2025-64393 is a critical (CVSS v4.0 9.4) remote code execution vulnerability in Veeam Backup & Replication version 12. Per Veeam KB4934 and NVD, untrusted data received through the Mount Service can be insecurely deserialized (CWE-502), allowing a user with only the low-privileged Backup Viewer role to execute arbitrary code on the Veeam Backup Server. NVD describes the result as code execution as SYSTEM. The CVSS v4.0 vector (AV:N/AC:L/AT:N/PR:L/UI:N, VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) indicates a network-reachable, low-complexity attack requiring low privileges and no user interaction, with complete impact on the vulnerable and subsequent systems. The flaw was reported through HackerOne.

The Mount Service is the Veeam component that provides mount functionality (for example file-level restore mount points) and is deployed on the Veeam backup server, on the standalone console, and on managed servers assigned the mount server role. Public sources do not describe the precise deserialization gadget, endpoint or wire protocol, and no proof-of-concept has been publicly validated.

Affected: Veeam Backup & Replication 12.3.2 P3 (build 12.3.2.4854) and all earlier version 12 builds. Fixed in 12.3.2 P4 (build 12.3.2.4934), disclosed in Veeam KB4934 on 2026-10-06 together with CVE-2026-93026 (medium, CVSS 4.0 6.1: a Backup Viewer could modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials) and CVE-2025-64392 (medium, CVSS 4.0 4.8: reflected XSS in Veeam Backup Enterprise Manager). Version 13 is not vulnerable.

As of the sources reviewed (Veeam KB4934, NVD, SOC Prime, SecurityOnline), no in-the-wild exploitation has been reported and no threat actor, malware or network IOC is named; the CVE is not in the CISA KEV catalog as of 2026-10-08. Backup servers are nevertheless a high-value target class: compromise enables credential theft, backup tampering or destruction, and ransomware facilitation, and a prior Veeam deserialization RCE (CVE-2024-40711) was exploited by Akira, Fog and Frag ransomware operators. Defenders should patch, restrict Backup Viewer role assignment, segment backup infrastructure, and monitor Backup Viewer authentication correlated with Mount Service activity and unexpected child processes or command execution on the backup server.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1555 Credentials from Password Stores
- T1490 Inhibit System Recovery
- T1485 Data Destruction

## Sources

- [Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 (KB4934)](https://www.veeam.com/kb4934)
- [NVD - CVE-2025-64393](https://nvd.nist.gov/vuln/detail/CVE-2025-64393)
- [CVE-2025-64393: Critical Veeam Backup & Replication RCE Vulnerability (SOC Prime)](https://socprime.com/blog/cve-2025-64393-critical-veeam-backup-replication-rce-vulnerability/)
- [Veeam Backup Vulnerability CVE-2025-64393 (SecurityOnline)](https://securityonline.info/veeam-backup-vulnerability-cve-2025-64393/)
- [CVE-2025-64393 (The Hacker Wire)](https://www.thehackerwire.com/vulnerability/CVE-2025-64393/)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Veeam Help Center - Mount Servers](https://helpcenter.veeam.com/docs/vbr/userguide/mount_server.html?ver=13)
- [CISA adds Veeam Backup and Replication flaw CVE-2024-40711 to KEV (Security Affairs)](https://securityaffairs.com/170014/SECURITY/U-S-CISA-ADDS-VEEAM-BACKUP-AND-REPLICATION-FLAW-TO-ITS-KNOWN-EXPLOITED-VULNERABILITIES-CATALOG.HTML)
- [Critical Vulnerability in Veeam Products Exploited by Ransomware Gangs (Cyble)](https://cyble.com/blog/critical-vulnerability-in-veeam-products-exploited-by-ransomware-gangs/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3191
