PT-2021-12853 · Acronis · Acronis True Image
Published
2021-05-25
·
Updated
2022-07-12
·
CVE-2020-9452
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Acronis True Image 2020 version 24.5.22510
Description:
An issue was discovered in the anti ransomware service.exe component, which includes functionality to quarantine files by copying a suspected ransomware file from one directory to another using SYSTEM privileges. Because unprivileged users have write permissions in the quarantine folder, it is possible to control this privileged write with a hardlink. This means that an unprivileged user can write/overwrite arbitrary files in arbitrary folders. Escalating privileges to SYSTEM is trivial with arbitrary writes. While the quarantine feature is not enabled by default, it can be forced to copy the file to the quarantine by communicating with anti ransomware service.exe through its REST API.
Recommendations:
For Acronis True Image 2020 version 24.5.22510, as a temporary workaround, consider disabling the quarantine feature until a patch is available. Restrict access to the quarantine folder to minimize the risk of exploitation. Avoid using the REST API to communicate with anti ransomware service.exe until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acronis True Image