PT-2021-12853 · Acronis · Acronis True Image

Published

2021-05-25

·

Updated

2022-07-12

·

CVE-2020-9452

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Acronis True Image 2020 version 24.5.22510
Description: An issue was discovered in the anti ransomware service.exe component, which includes functionality to quarantine files by copying a suspected ransomware file from one directory to another using SYSTEM privileges. Because unprivileged users have write permissions in the quarantine folder, it is possible to control this privileged write with a hardlink. This means that an unprivileged user can write/overwrite arbitrary files in arbitrary folders. Escalating privileges to SYSTEM is trivial with arbitrary writes. While the quarantine feature is not enabled by default, it can be forced to copy the file to the quarantine by communicating with anti ransomware service.exe through its REST API.
Recommendations: For Acronis True Image 2020 version 24.5.22510, as a temporary workaround, consider disabling the quarantine feature until a patch is available. Restrict access to the quarantine folder to minimize the risk of exploitation. Avoid using the REST API to communicate with anti ransomware service.exe until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9452

Affected Products

Acronis True Image