PT-2021-12852 · Acronis · Acronis True Image
Published
2021-05-25
·
Updated
2021-06-03
·
CVE-2020-9451
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Acronis True Image 2020 version 24.5.22510
Description:
An issue was discovered where the
anti ransomware service.exe keeps a log in a folder with write permissions for unprivileged users. The logs follow a predictable pattern, allowing an unprivileged user to create a hardlink from a log file to anti ransomware service.exe. On reboot, this forces the service to try to write its log into its own process, resulting in a SHARING VIOLATION crash, which occurs on every reboot.Recommendations:
For Acronis True Image 2020 version 24.5.22510, consider restricting write permissions to the log folder to prevent unprivileged users from creating hardlinks to
anti ransomware service.exe until a patch is available. As a temporary workaround, disabling the anti ransomware service.exe service until a fix is provided could mitigate the risk of the SHARING VIOLATION crash. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acronis True Image