PT-2023-5805 · Acronis · Acronis Cyber Protect Home Office

Tkoyeung

·

Published

2023-09-20

·

Updated

2023-12-10

·

CVE-2023-5042

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Acronis Cyber Protect Home Office (Windows) versions before build 40713
Description The issue is related to sensitive information disclosure due to insecure folder permissions. This could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions before build 40713, update to build 40713 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive folders to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2023-06491
CVE-2023-5042

Affected Products

Acronis Cyber Protect Home Office