Local Privilege Escalation in Acronis Snap Deploy for Windows
CVE-2025-24826

6.7MEDIUM

Key Information:

Vendor

Acronis

Vendor
CVE Published:
28 January 2025

What is CVE-2025-24826?

A vulnerability exists in Acronis Snap Deploy for Windows due to improper folder permissions, which could allow a local attacker to escalate privileges. This vulnerability impacts versions prior to build 4625. Users are encouraged to apply the recommended updates to safeguard their systems against potential exploitation.

Affected Version(s)

Acronis Snap Deploy Windows < 4625

References

CVSS V3.0

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@wdormann (https://hackerone.com/wdormann)
.