7.8

CVE-2022-45455

Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107, Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Acronis ≫ Agent Version < c22.07
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update -
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update update1
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update update2
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update update3
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update update4
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Home Office Version -
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.044
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@acronis.com 6.6 0.8 5.3
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L
CWE-459 Incomplete Cleanup

The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

https://security-advisory.acronis.com/advisories/SEC-4459
Vendor Advisory