Local Privilege Escalation in Acronis Cyber Protect Home Office for Windows
CVE-2022-46869

7.3HIGH

Key Information:

Vendor
Acronis
Vendor
CVE Published:
31 August 2023

Summary

A vulnerability exists in Acronis Cyber Protect Home Office for Windows that allows local privilege escalation due to improper handling of soft links. Attackers could exploit this flaw during the installation process, potentially gaining elevated privileges on the affected system. Organizations using versions prior to build 40278 are advised to update their software to mitigate such risks. Ensure regular updates and patches are applied to protect against this and other vulnerabilities.

Affected Version(s)

Acronis Cyber Protect Home Office Windows < 40278

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@imag0r (https://hackerone.com/imag0r)
.