PT-2026-46063 · Acronis · Devicelock Dlp
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Acronis DeviceLock DLP (Windows) versions prior to 9.0.15051.93227
Description
Local privilege escalation is possible due to an EXE hijacking issue. This occurs when an application searches for a required executable file in an insecure order, allowing an attacker to place a malicious executable in a higher-priority directory to be executed with elevated privileges.
Recommendations
Update to build 9.0.15051.93227 or later.
Fix
LPE
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devicelock Dlp