Acronis Cyber Protect
cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*, +1 more
- < 39169
A local privilege escalation vulnerability has been identified in the Tray Monitor service of Acronis Cyber Protect 16 and Acronis Cyber Protect Cloud Agent. This issue arises from excessive permissions assigned to the service, allowing unauthorized users to gain elevated privileges. The vulnerability affects Acronis Cyber Protect 16 (Linux, macOS, Windows) prior to build 39169, and Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) prior to build 35895.
Exploitation of this vulnerability allows for local privilege escalation, enabling users to gain unauthorized elevated privileges on the system.
Users can update to Acronis Cyber Protect 16 Update 3 or Acronis Cyber Protect Cloud Agent update C23.07 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.