Excessive Privileges in Acronis Agent Lead to Code Execution and Sensitive Information Disclosure

Excessive Privileges in Acronis Agent Lead to Code Execution and Sensitive Information Disclosure

CVE-2022-3405 · HIGH Severity

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.