PT-2021-11717 · Acronis · Acronis True Image
Published
2021-01-29
·
Updated
2021-07-21
·
CVE-2020-35145
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Acronis True Image for Windows versions prior to 2021 Update 3
Description:
The issue allows local privilege escalation due to a DLL hijacking vulnerability in multiple components, also known as an Untrusted Search Path issue. This means that an attacker can potentially exploit the vulnerability by placing a malicious DLL in a location where it will be loaded by the application, allowing them to gain elevated privileges.
Recommendations:
For Acronis True Image for Windows versions prior to 2021 Update 3, update to 2021 Update 3 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable components to minimize the risk of exploitation.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acronis True Image