VulnerabilityModified
CVE-2021-44204
Local privilege escalation via named pipe due to improper access control checks.
HIGH 7.8EPSS 0.20%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- acronis/true image · acronis/agent · acronis/cyber protect · acronis/cyber protect home office
- Source
- security@acronis.com
References
- https://security-advisory.acronis.com/advisories/SEC-2355Vendor Advisory
- https://security-advisory.acronis.com/advisories/SEC-2355Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.