Local Privilege Escalation in Acronis Cyber Protect Products
CVE-2022-45451
Summary
A vulnerability exists in Acronis products that allows local privilege escalation due to insecure permissions on the driver communication port. This issue affects multiple versions of Acronis software, including Acronis Cyber Protect Home Office, Acronis Agent, and Acronis Cyber Protect 15. Users of these products are advised to update to the latest versions to mitigate this security risk. For more information, refer to Acronis advisory documents SEC-4858 and SEC-5487.
Affected Version(s)
Acronis Agent Windows < 30600
Acronis Cyber Protect 15 Windows < 30984
Acronis Cyber Protect Home Office Windows < 40173
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
Vulnerability published
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability Reserved