First published: Fri Jul 03 2020(Updated: )
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam Veeam Availability Suite | <10.0 | |
Veeam Veeam Backup \& Replication | <10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15518 is a vulnerability in Veeam Availability Suite and Veeam Backup & Replication that allows unprivileged users to achieve total control over filesystem I/O requests.
CVE-2020-15518 affects Veeam Availability Suite before version 10 and Veeam Backup & Replication before version 10.
CVE-2020-15518 has a severity of 8.8 (high).
Unprivileged users can exploit CVE-2020-15518 to gain total control over filesystem I/O requests.
To fix CVE-2020-15518, update Veeam Availability Suite and Veeam Backup & Replication to version 10 or later.