Web Hack List

Collected research

By Executive Order, We Are Banning Blacklists: Domain-Level RCE in Veeam Backup and Replication (CVE-2025-23120)

Traces a Veeam .NET Remoting chain through an allowed outer object and denylisted inner deserialization. Product-specific DataSet subclasses inherit dangerous parent behavior while escaping class-name checks; the source also follows Windows Users membership to explain the conditions under which an ordinary domain account reaches the sink.

Record

Researcher
Piotr Bazydlo and Sina Kheirkhah
Published by
watchTowr
Date
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Piotr Bazydlo and Sina Kheirkhah, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .