SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-44204

Local privilege escalation via named pipe due to improper access control checks.

HIGH 7.8EPSS 0.20%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.20% probability · 10th percentile
CISA KEV
Not listed
Weakness
CWE-285
Affected
acronis/true image · acronis/agent · acronis/cyber protect · acronis/cyber protect home office
Source
security@acronis.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.