Local Privilege Escalation in Acronis Cyber Protect Home Office for Windows
CVE-2022-46869
7.3HIGH
Key Information:
- Vendor
- Acronis
- Vendor
- CVE Published:
- 31 August 2023
Summary
A vulnerability exists in Acronis Cyber Protect Home Office for Windows that allows local privilege escalation due to improper handling of soft links. Attackers could exploit this flaw during the installation process, potentially gaining elevated privileges on the affected system. Organizations using versions prior to build 40278 are advised to update their software to mitigate such risks. Ensure regular updates and patches are applied to protect against this and other vulnerabilities.
Affected Version(s)
Acronis Cyber Protect Home Office Windows < 40278
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
@imag0r (https://hackerone.com/imag0r)