SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24113

Local privilege escalation due to excessive permissions assigned to child processes.

HIGH 7.8EPSS 0.21%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.21% probability · 11th percentile
CISA KEV
Not listed
Weakness
CWE-250, CWE-276
Affected
acronis/agent · acronis/cyber protect · acronis/cyber protect home office · acronis/true image
Source
security@acronis.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.