7.8

CVE-2023-41743

Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis Cyber Protect Cloud Agent (Windows) before build 31637, Acronis Cyber Protect 15 (Windows) before build 35979, Acronis True Image OEM (Windows) before build 42575.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Acronis ≫ Agent Version < c23.02
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update -
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update update1
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update update2
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update update3
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update update4
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Version 15 Update update5
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Home Office Version -
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Home Office Version 39900
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Home Office Version 40107
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Home Office Version 40173
   Microsoft ≫ Windows Version -
Acronis ≫ Cyber Protect Home Office Version 40208
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.169
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@acronis.com 8.8 2 6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://security-advisory.acronis.com/SEC-4858
Vendor Advisory
Release Notes
https://security-advisory.acronis.com/advisories/SEC-5487
Vendor Advisory
Release Notes