Local Privilege Escalation Vulnerability in Acronis Cyber Protect Cloud Agent for Windows
CVE-2025-48959

6.7MEDIUM

Key Information:

Vendor

Acronis

Vendor
CVE Published:
4 June 2025

What is CVE-2025-48959?

A vulnerability has been identified in Acronis Cyber Protect Cloud Agent (Windows) that allows local privilege escalation due to insecure file permissions. This security weakness may enable users to gain elevated privileges on the system, potentially leading to unauthorized access or control over sensitive data and resources. It is crucial for users of affected versions to update to build 40077 or later as part of their security measures to mitigate the risk presented by this vulnerability.

Affected Version(s)

Acronis Cyber Protect Cloud Agent Windows < 40077

References

CVSS V3.0

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@mad31k (https://hackerone.com/mad31k)
.