VYPR
High severity8.8NVD Advisory· Published Jul 3, 2020· Updated Jun 17, 2026

CVE-2020-15518

CVE-2020-15518

Description

VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.

Affected products

5
  • Veeam/Availability Suitellm-fuzzy3 versions
    <10+ 2 more
    • (no CPE)range: <10
    • (no CPE)
    • cpe:2.3:a:veeam:veeam_availability_suite:*:*:*:*:*:*:*:*range: <10.0
  • <10+ 1 more
    • (no CPE)range: <10
    • cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*range: <10.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.