Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » VEEAM and IBM release patches for high -risk disadvantages in backup and AIX Systems
Global Security

VEEAM and IBM release patches for high -risk disadvantages in backup and AIX Systems

AdminBy AdminMarch 20, 2025No Comments2 Mins Read
Veeam and IBM
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


March 20, 2025Red LakshmananUpdate vulnerability / software

Veeam and ibm

Veeam has released security updates to address a critical security deficiency that affects its backup software and replication, which can lead to the remote code.

Vulnerability tracked as Cve-2025-23120Carries CVSS 9.9 out of 10.0. This affects 12.3.0.310 and all previous versions 12.

“The vulnerability that allows you – Note in a consultation released on Wednesday.

Petr Basidlo Safety Researcher with Watchtowr was credited and the shortage report, which was resolved in version 12.3.1 (collection 12.3.1139).

According to Bazydlo and Researcher Sina Hirha, CVE-2025-23120 stems from the inconspicuous management of the VEEAM desserization mechanism, which causes a class that can be deasserized to pave the way to internal dessertization that implements the block-based approach.

It also means that the actor threats can use a gadget for desserization, missing in the block -leaf – namely: veeam.backup.esxanager.xmlframeworkds and veeam.backup.core.backupsumary – to achieve the remote code.

Cybersecurity

“These vulnerabilities can be used by any user who belongs to a group of local users on the leading Windows of your veeam server,” – researchers – Note. “Better yet – if you joined your server to the domain, these vulnerabilities can be used by any domain user.”

The Patch Introduced VEEAM adds two gadgets to the existing block -list, which means that the decision can again be sensitive to such risks if other possible desserization is detected.

Development comes the way IBM Starting fixes To eliminate two important errors in their AIX operating system, which can allow team execution.

List of flaws affecting AIX 7.2 and 7.3 versions, below – below –

  • Cve-2024-56346 (CVSS assessment: 10.0) – Incorrect vulnerability of access control that can allow remote attackers to perform arbitrary commands through the Nimessis nimesis nimesis service service
  • Cve-2024-56347 (CVSS assessment: 9.6) – Incorrect vulnerability of access control that can allow remote attackers to perform arbitrary commands through AIX NIMSH SERVICE/TLS protection mechanism

While there is no evidence that any of these critical deficiencies has been used in the wild, users are advised to move quickly to apply the necessary patches to provide potential threats.

Found this article interesting? Keep track of us next Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.