← back
CVE-2022-3405criticalCWE-269

CVE-2022-3405

43Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 9.3epss 5.3%
from disclosure to weapon0 days
Published on NVDMay 3
metasploitNov 8
exploitation probability
5.3%top 8% of all CVEs
observed exploitation
nono source reports it
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N