Impact
Acronis Cyber Protect 17 on Windows may allow a local user with limited rights to gain administrative privileges by exploiting improperly set directory permissions. This flaw enables the user to modify application files or configuration data, which can lead to execution of arbitrary code or escalation to higher privileges. The weakness corresponds to CWE-276, improper authorization.
Affected Systems
The vulnerability affects Acronis Cyber Protect 17 for Windows in builds prior to 41186. Users running older versions should verify their build number and consider upgrading to a supported release.
Risk and Exploitability
The CVSS score of 5.0 indicates medium severity. The Economics of Security Predictions Service shows a low exploitation probability (<1 %). The vulnerability is not listed in the CISA KEV catalog. While no publicly documented exploit exists, the local attacker requirement means any machine with untrusted local accounts or weak user isolation could be targeted, making timely remediation advisable.
OpenCVE Enrichment