Local Privilege Escalation in Acronis Cyber Protect Home Office for Windows
CVE-2022-46868

6.7MEDIUM

Key Information:

Vendor
Acronis
Vendor
CVE Published:
31 August 2023

Summary

The vulnerability arises from improper handling of soft links during recovery processes in Acronis Cyber Protect Home Office for Windows. Attackers may exploit this flaw to gain elevated privileges on affected systems, potentially compromising user data and system integrity. It is crucial for users running versions prior to build 40173 to update their software to mitigate risks associated with this issue.

Affected Version(s)

Acronis Cyber Protect Home Office Windows < 40173

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@z3ron3 (https://hackerone.com/z3ron3)
.