Local Privilege Escalation in Acronis Cyber Protect Products
CVE-2023-45248

7.3HIGH

Key Information:

Vendor
Acronis
Vendor
CVE Published:
9 October 2023

Summary

A local privilege escalation vulnerability exists in Acronis Cyber Protect products due to improper handling of dynamic-link library (DLL) files, allowing an attacker to leverage this flaw for unauthorized access and execution of arbitrary code. This issue impacts versions prior to build 36497 of Acronis Cyber Protect Cloud Agent and versions before build 37391 of Acronis Cyber Protect 16, presenting potential risks for users and organizations relying on these solutions.

Affected Version(s)

Acronis Cyber Protect 16 Windows < 37391

Acronis Cyber Protect Cloud Agent Windows < 36497

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.