CVE-2020-15496
- EPSS 0.03%
- Veröffentlicht 15.07.2021 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:38
Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.
CVE-2020-35145
- EPSS 0.13%
- Veröffentlicht 29.01.2021 07:15:17
- Zuletzt bearbeitet 21.11.2024 05:26:51
Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components, aka an Untrusted Search Path issue.
CVE-2020-10140
- EPSS 0.05%
- Veröffentlicht 21.10.2020 14:15:15
- Zuletzt bearbeitet 21.11.2024 04:54:53
Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileg...
CVE-2020-10139
- EPSS 0.05%
- Veröffentlicht 21.10.2020 14:15:15
- Zuletzt bearbeitet 21.11.2024 04:54:53
Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis True Image contains a privileged service that uses this OpenSSL component. Because unprivileged Windows us...
CVE-2017-3219
- EPSS 0.03%
- Veröffentlicht 21.06.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
- EPSS 1.19%
- Veröffentlicht 10.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Acronis True Image Group Server 1.5.19.191 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a packet with an invalid length fi...
- EPSS 1.38%
- Veröffentlicht 10.03.2008 23:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Acronis True Image Windows Agent 1.0.0.54 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a malformed packet to port 9876, wh...