VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15518
Reference (s):
- https://zwclose.github.io/veeamon

