Local Privilege Escalation in Acronis Cyber Protect Products
CVE-2022-45455
6.6MEDIUM
Key Information:
- Vendor
- Acronis
- Vendor
- CVE Published:
- 13 February 2023
Summary
This vulnerability allows local privilege escalation due to incomplete uninstallation cleanup in several Acronis products, potentially allowing attackers to gain elevated access to system resources. Specific builds of Acronis Cyber Protect Home Office, Acronis Agent, and Acronis Cyber Protect 15 are affected, highlighting the importance of applying the latest updates and patches to ensure system integrity and security.
Affected Version(s)
Acronis Agent Windows < 30025
Acronis Cyber Protect 15 Windows < 30984
Acronis Cyber Protect Home Office Windows < 40107
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
@tkoyeung (https://hackerone.com/tkoyeung)