8.8

CVE-2023-41743

Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis Agent (Windows) before build 31637, Acronis Cyber Protect 15 (Windows) before build 35979.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AcronisAgent Version < c23.02
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Update-
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Updateupdate1
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Updateupdate2
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Updateupdate3
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Updateupdate4
   MicrosoftWindows Version-
AcronisCyber Protect Version15 Updateupdate5
   MicrosoftWindows Version-
AcronisCyber Protect Home Office Version-
   MicrosoftWindows Version-
AcronisCyber Protect Home Office Version39900
   MicrosoftWindows Version-
AcronisCyber Protect Home Office Version40107
   MicrosoftWindows Version-
AcronisCyber Protect Home Office Version40173
   MicrosoftWindows Version-
AcronisCyber Protect Home Office Version40208
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.051
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@acronis.com 8.8 2 6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.