CVE-2020-9451: Medium severity acronis true image vulnerability
An issue was discovered in Acronis True Image 2020 24.5.22510. antiransomwareservice.exe keeps a log in a folder where unprivileged users have write permissions. The logs are generated in a predictable pattern, allowing an unprivileged user to create a hardlink from a (not yet created) log file to antiransomwareservice.exe. On reboot, this forces the antiransomwareservice to try to write its log into its own process, crashing in a SHARING VIOLATION. This crash occurs on every reboot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9451?
CVE-2020-9451 is considered to be of medium severity due to its potential for exploitation by an unprivileged user.
How can I fix CVE-2020-9451?
To mitigate CVE-2020-9451, ensure that the log folder for anti_ransomware_service.exe has restricted permissions that prevent unprivileged users from writing to it.
What types of systems are affected by CVE-2020-9451?
CVE-2020-9451 affects Acronis True Image 2020 version 24.5.22510 specifically.
What exploitation techniques can be used against CVE-2020-9451?
An unprivileged user can exploit CVE-2020-9451 by creating a hardlink to a log file that is expected to be generated by anti_ransomware_service.exe.
Is CVE-2020-9451 being actively exploited?
As of the last report, there have been no confirmed active exploits in the wild for CVE-2020-9451.