CVE-2020-10140: High severity acronis true image vulnerability
Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileges by placing a DLL in one of several paths within C:\ProgramData\Acronis.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10140?
CVE-2020-10140 is a vulnerability in Acronis True Image 2021 that allows an unprivileged user to achieve arbitrary code execution with SYSTEM privileges.
How does CVE-2020-10140 occur?
CVE-2020-10140 occurs because Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory.
How can an attacker exploit CVE-2020-10140?
An attacker can exploit CVE-2020-10140 by placing a DLL in one of several paths within the C:\ProgramData\Acronis directory.
What is the severity of CVE-2020-10140?
CVE-2020-10140 has a severity rating of 7.3 (high).
How do I fix CVE-2020-10140?
To fix CVE-2020-10140, update Acronis True Image 2021 to the latest version or apply the vendor-supplied patch.