Local Privilege Escalation in Acronis Cyber Protect Products
CVE-2022-45455

6.6MEDIUM

Key Information:

Summary

This vulnerability allows local privilege escalation due to incomplete uninstallation cleanup in several Acronis products, potentially allowing attackers to gain elevated access to system resources. Specific builds of Acronis Cyber Protect Home Office, Acronis Agent, and Acronis Cyber Protect 15 are affected, highlighting the importance of applying the latest updates and patches to ensure system integrity and security.

Affected Version(s)

Acronis Agent Windows < 30025

Acronis Cyber Protect 15 Windows < 30984

Acronis Cyber Protect Home Office Windows < 40107

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@tkoyeung (https://hackerone.com/tkoyeung)
.