Vulnerabilidades en Acronis

193 resultados
Análisis Vexday

Com 192 CVEs catalogadas, o portfólio de vulnerabilidades da Acronis apresenta uma taxa de exploração ativa acima da média geral do catálogo CISA KEV — proporção 1,2 vezes superior ao índice de referência —, o que indica atenção redobrada para equipes de resposta a incidentes. A CVE mais crítica em exploração confirmada é a CVE-2023-45249, com score EPSS de 0,5354, sugerindo probabilidade relevante de tentativas de exploração observadas em ambiente real. O tipo de falha mais recorrente é CWE-427 (uncontrolled search path element), classe que frequentemente permite escalonamento de privilégios ou execução de código por meio de dependências mal controladas. As 11 CVEs surgidas nos últimos 90 dias e as 8 de severidade crítica reforçam a necessidade de ciclos de patching ágeis para produtos Acronis em ambientes corporativos.

CVE-2025-24829MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2025-24827MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2024-8903MEDIUMLocal active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: AcronisEPSS 0.1%CVE-2025-30407MEDIUMLocal privilege escalation due to a binary hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (EPSS 0.1%CVE-2024-34012MEDIUMLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before bEPSS 0.1%CVE-2025-9578HIGHLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2025-48959MEDIUMLocal privilege escalation due to insecure file permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (WindowsEPSS 0.1%CVE-2025-24826MEDIUMLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2025-7779HIGHLocal privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) beforeEPSS 0.1%CVE-2022-4418HIGHLocal privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect HomEPSS 0.1%CVE-2026-28725MEDIUMSensitive information disclosure due to improper configuration of a headless browser. The following products are affected: Acronis Cyber ProEPSS 0.1%CVE-2025-11792HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2026-50033HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before EPSS 0.1%CVE-2026-44682HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before EPSS 0.1%CVE-2026-28717MEDIUMLocal privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) beEPSS 0.1%CVE-2025-11790MEDIUMCredentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud AgentEPSS 0.1%CVE-2024-55539LOWWeak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185, EPSS 0.1%CVE-2024-56414MEDIUMWeb installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (Windows) before buildEPSS 0.1%CVE-2026-41220HIGHLocal privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before buEPSS 0.1%CVE-2026-41952HIGHLocal privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before buEPSS 0.1%