CVE-2020-15518: High severity veeam availability suite vulnerability
Published Jul 3, 2020
·Updated
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.
Affected Software
2 affected components
Veeam Veeam Availability Suite<10.0
Veeam Veeam Backup \& Replication<10.0
Event History
Jul 3, 2020
CVE Published
via MITRE·10:58 AM
Data Sourced
via MITRE·10:58 AM
Description
Frequently Asked Questions
1
What is CVE-2020-15518?
CVE-2020-15518 is a vulnerability in Veeam Availability Suite and Veeam Backup & Replication that allows unprivileged users to achieve total control over filesystem I/O requests.
2
How does CVE-2020-15518 affect Veeam Availability Suite and Veeam Backup & Replication?
CVE-2020-15518 affects Veeam Availability Suite before version 10 and Veeam Backup & Replication before version 10.
3
What is the severity of CVE-2020-15518?
CVE-2020-15518 has a severity of 8.8 (high).
4
How can unprivileged users exploit CVE-2020-15518?
Unprivileged users can exploit CVE-2020-15518 to gain total control over filesystem I/O requests.
5
How can I fix CVE-2020-15518 in Veeam Availability Suite and Veeam Backup & Replication?
To fix CVE-2020-15518, update Veeam Availability Suite and Veeam Backup & Replication to version 10 or later.