Local Privilege Escalation in Acronis Cyber Protect Products
CVE-2023-45248
7.3HIGH
Key Information:
- Vendor
- Acronis
- Vendor
- CVE Published:
- 9 October 2023
Summary
A local privilege escalation vulnerability exists in Acronis Cyber Protect products due to improper handling of dynamic-link library (DLL) files, allowing an attacker to leverage this flaw for unauthorized access and execution of arbitrary code. This issue impacts versions prior to build 36497 of Acronis Cyber Protect Cloud Agent and versions before build 37391 of Acronis Cyber Protect 16, presenting potential risks for users and organizations relying on these solutions.
Affected Version(s)
Acronis Cyber Protect 16 Windows < 37391
Acronis Cyber Protect Cloud Agent Windows < 36497
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved