7.8

CVE-2022-45455

Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107, Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.

Data is provided by the National Vulnerability Database (NVD)
AcronisAgent Version < c22.07
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Update-
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Updateupdate1
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Updateupdate2
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Updateupdate3
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Updateupdate4
   MicrosoftWindows Version-
AcronisCyber Protect Home Office Version-
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.16
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@acronis.com 6.6 0.8 5.3
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L
CWE-459 Incomplete Cleanup

The product does not properly "clean up" and remove temporary or supporting resources after they have been used.