CVE-2020-25736: High severity acronis true image vulnerability
Published Jul 15, 2021
·Updated
Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.
Affected Software
5 affected components
Acronis True Image Macos=2019-1
Acronis True Image Macos=2019-2
Acronis True Image Macos=2019-3
Acronis True Image Macos=2020
Acronis True Image Macos=2021-1
Event History
Jul 15, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-25736.
2
What is the severity of CVE-2020-25736?
The severity of CVE-2020-25736 is high with a CVSS score of 7.8.
3
Which versions of Acronis True Image on macOS are affected?
Acronis True Image 2019 update 1 through 2021 update 1 on macOS are affected.
4
How does CVE-2020-25736 allow local privilege escalation?
CVE-2020-25736 allows local privilege escalation due to an insecure XPC service configuration.
5
Where can I find more information about CVE-2020-25736?
You can find more information about CVE-2020-25736 on the following references: [Packet Storm Security](http://packetstormsecurity.com/files/170246/Acronis-TrueImage-XPC-Privilege-Escalation.html), [Acronis Knowledge Base](https://kb.acronis.com/content/68061), [Acronis Blog](https://www.acronis.com/en-us/blog/).