Description
Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileges by placing a DLL in one of several paths within C:\ProgramData\Acronis.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-2603 | Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileges by placing a DLL in one of several paths within C:\ProgramData\Acronis. |
References
| Link | Providers |
|---|---|
| https://www.kb.cert.org/vuls/id/114757 |
|
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-04T10:50:57.928Z
Reserved: 2020-03-05T00:00:00.000Z
Link: CVE-2020-10140
No data.
Status : Modified
Published: 2020-10-21T14:15:15.247
Modified: 2024-11-21T04:54:53.963
Link: CVE-2020-10140
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD