PT-2023-5788 · Acronis · Acronis Cyber Protect 16+2

CVE-2023-45248

·

Publicado

2023-10-09

·

Atualizado

2024-02-27

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Acronis Cyber Protect Cloud Agent (Windows) versions before build 36497 Acronis Cyber Protect 16 (Windows) versions before build 37391 Acronis Agent (Windows) versions before build 36497
Description The issue is related to a local privilege escalation due to a DLL hijacking vulnerability. This vulnerability is associated with an uncontrolled search path element. Exploitation of the vulnerability may allow an attacker to elevate their privileges.
Recommendations For Acronis Cyber Protect Cloud Agent (Windows) versions before build 36497, update to build 36497 or later. For Acronis Cyber Protect 16 (Windows) versions before build 37391, update to build 37391 or later. For Acronis Agent (Windows) versions before build 36497, update to build 36497 or later. As a temporary workaround, consider restricting access to vulnerable components until a patch is available.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06474
CVE-2023-45248

Produtos afetados

Acronis Agent
Acronis Cyber Protect 16
Acronis Cyber Protect Cloud Agent