First published: Wed Oct 21 2020(Updated: )
Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileges by placing a DLL in one of several paths within C:\ProgramData\Acronis.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Acronis True Image | =2021 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10140 is a vulnerability in Acronis True Image 2021 that allows an unprivileged user to achieve arbitrary code execution with SYSTEM privileges.
CVE-2020-10140 occurs because Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory.
An attacker can exploit CVE-2020-10140 by placing a DLL in one of several paths within the C:\ProgramData\Acronis directory.
CVE-2020-10140 has a severity rating of 7.3 (high).
To fix CVE-2020-10140, update Acronis True Image 2021 to the latest version or apply the vendor-supplied patch.