CVE-2020-15518

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/07/2020
Last modified:
21/07/2021

Description

VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:veeam:veeam_availability_suite:*:*:*:*:*:*:*:* 10.0 (excluding)
cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:* 10.0 (excluding)


References to Advisories, Solutions, and Tools