Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xm7v-g2x4-x85v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileges by placing a DLL in one of several paths within C:\ProgramData\Acronis.

Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileges by placing a DLL in one of several paths within C:\ProgramData\Acronis.

EPSS

Процентиль: 14%
0.00045
Низкий

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
nvd
больше 5 лет назад

Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileges by placing a DLL in one of several paths within C:\ProgramData\Acronis.

EPSS

Процентиль: 14%
0.00045
Низкий

Дефекты

CWE-732