CVE-2021-35971
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

Veeam Backup and Replication versions 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 contained a vulnerability related to mishandling deserialization during Microsoft .NET remoting. The vulnerability was discovered and reported by Markus Wulftange from Code White, and was assigned CVE-2021-35971 on June 30, 2021 (CVE Mitre, NVD).

Technical details

The vulnerability was identified as a deserialization issue in the Microsoft .NET remoting functionality of Veeam Backup and Replication. The CVSS v3.1 base score for this vulnerability is 9.8 (Critical), with the following vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This indicates the vulnerability can be exploited remotely with no required privileges or user interaction (NVD).

Impact

Given the critical CVSS score and vector details, successful exploitation of this vulnerability could lead to remote code execution with high impacts on confidentiality, integrity, and availability of the affected systems (NVD).

Mitigation and workarounds

Veeam addressed this vulnerability by releasing patches for both affected versions. Users of version 10 should upgrade to build 10.0.1.4854 P20210609 or later, while users of version 11 should upgrade to build 11.0.0.837 P20210507 or later. The patches include changes to the Microsoft .NET remoting deserialization logic (Veeam KB4126, Veeam KB4180).

Additional resources


SourceThis report was generated using AI

Related Veeam Backup & Replication vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48983CRITICAL9.9
  • Veeam Backup & ReplicationVeeam Backup & Replication
  • cpe:2.3:a:veeam:backup_and_replication
NoYesOct 31, 2025
CVE-2025-48984HIGH8.8
  • Veeam Backup & ReplicationVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesOct 31, 2025
CVE-2025-23121HIGH8.8
  • Veeam Backup & ReplicationVeeam Backup & Replication
  • cpe:2.3:a:veeam:backup_and_replication
NoYesJun 19, 2025
CVE-2025-48982HIGH7.8
  • Veeam Backup & ReplicationVeeam Backup & Replication
  • cpe:2.3:a:veeam:backup_and_replication
NoYesOct 31, 2025
CVE-2025-24286MEDIUM4.9
  • Veeam Backup & ReplicationVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesJun 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management