Local Privilege Escalation in Acronis Cyber Protect 16 by Acronis
CVE-2024-55543

7.8HIGH

Key Information:

Vendor
Acronis
Vendor
CVE Published:
2 January 2025

Summary

Acronis Cyber Protect 16 contains a local privilege escalation vulnerability attributed to DLL hijacking. This vulnerability can allow unauthorized users to gain elevated privileges on affected systems. Specifically, users with local access can exploit this weakness to execute malicious code, potentially compromising the integrity and confidentiality of the system. It is crucial for users to update to build 39169 or later to mitigate the associated risks. For further details, refer to vendor advisory SEC-6418.

Affected Version(s)

Acronis Cyber Protect 16 Windows < 39169

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@jtonner14 (https://hackerone.com/jtonner14)
.