Local Privilege Escalation Vulnerability in Acronis DeviceLock DLP (Windows)
CVE-2026-44609

7.3HIGH

Key Information:

Vendor

Acronis

Vendor
CVE Published:
3 June 2026

What is CVE-2026-44609?

Acronis DeviceLock DLP (Windows) is susceptible to a local privilege escalation vulnerability caused by EXE hijacking. Attackers can exploit this weakness in versions prior to build 9.0.15051.93227 to gain unauthorized access to system resources, potentially allowing them to execute arbitrary code with escalated privileges. It’s crucial for users of Acronis DeviceLock DLP to update their software to mitigate this threat.

Affected Version(s)

Acronis DeviceLock DLP Windows < 9.0.15051.93227

References

CVSS V3.0

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@mmg (https://hackerone.com/mmg)
.