CVE-2022-24113
Local privilege escalation due to excessive permissions assigned to child processes
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287
Una escalada de privilegios local debido a permisos excesivos asignados a los procesos hijos. Los siguientes productos están afectados: Acronis Cyber Protect 15 (Windows) versiones anteriores a la compilación 28035, Acronis Agent (Windows) versiones anteriores a la compilación 27147, Acronis Cyber Protect Home Office (Windows) versiones anteriores a la compilación 39612, Acronis True Image 2021 (Windows) versiones anteriores a la compilación 39287
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-28 CVE Reserved
- 2022-02-04 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-250: Execution with Unnecessary Privileges
- CWE-276: Incorrect Default Permissions
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security-advisory.acronis.com/advisories/SEC-2881 | 2022-02-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Acronis Search vendor "Acronis" | Agent Search vendor "Acronis" for product "Agent" | < c21.06 Search vendor "Acronis" for product "Agent" and version " < c21.06" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Acronis Search vendor "Acronis" | Cyber Protect Search vendor "Acronis" for product "Cyber Protect" | 15 Search vendor "Acronis" for product "Cyber Protect" and version "15" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Acronis Search vendor "Acronis" | Cyber Protect Search vendor "Acronis" for product "Cyber Protect" | 15 Search vendor "Acronis" for product "Cyber Protect" and version "15" | update1 |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Acronis Search vendor "Acronis" | Cyber Protect Search vendor "Acronis" for product "Cyber Protect" | 15 Search vendor "Acronis" for product "Cyber Protect" and version "15" | update2 |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Acronis Search vendor "Acronis" | Cyber Protect Home Office Search vendor "Acronis" for product "Cyber Protect Home Office" | - | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Acronis Search vendor "Acronis" | True Image Search vendor "Acronis" for product "True Image" | 2021 Search vendor "Acronis" for product "True Image" and version "2021" | windows |
Affected
| ||||||
Acronis Search vendor "Acronis" | True Image Search vendor "Acronis" for product "True Image" | 2021 Search vendor "Acronis" for product "True Image" and version "2021" | update_1, windows |
Affected
| ||||||
Acronis Search vendor "Acronis" | True Image Search vendor "Acronis" for product "True Image" | 2021 Search vendor "Acronis" for product "True Image" and version "2021" | update_2, windows |
Affected
| ||||||
Acronis Search vendor "Acronis" | True Image Search vendor "Acronis" for product "True Image" | 2021 Search vendor "Acronis" for product "True Image" and version "2021" | update_3, windows |
Affected
| ||||||
Acronis Search vendor "Acronis" | True Image Search vendor "Acronis" for product "True Image" | 2021 Search vendor "Acronis" for product "True Image" and version "2021" | update_4, windows |
Affected
| ||||||
Acronis Search vendor "Acronis" | True Image Search vendor "Acronis" for product "True Image" | 2021 Search vendor "Acronis" for product "True Image" and version "2021" | update_5, windows |
Affected
|