PT-2021-11717 · Acronis · Acronis True Image

Published

2021-01-29

·

Updated

2021-07-21

·

CVE-2020-35145

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Acronis True Image for Windows versions prior to 2021 Update 3
Description: The issue allows local privilege escalation due to a DLL hijacking vulnerability in multiple components, also known as an Untrusted Search Path issue. This means that an attacker can potentially exploit the vulnerability by placing a malicious DLL in a location where it will be loaded by the application, allowing them to gain elevated privileges.
Recommendations: For Acronis True Image for Windows versions prior to 2021 Update 3, update to 2021 Update 3 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable components to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35145

Affected Products

Acronis True Image