CVE-2021-38086: High severity Acronis Cyber Protect vulnerability
Published Aug 12, 2021
·Updated
Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.
Affected Software
8 affected components
Acronis Cyber Protect<15
Acronis Cyber Protect=15
Acronis Cyber Protect=15-update1
Microsoft Windows
All of the following
Any of the following
Acronis Cyber Protect<15
Acronis Cyber Protect=15
Acronis Cyber Protect=15-update1
Microsoft Windows
Event History
Aug 12, 2021
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2021-38086.
2
What software versions are affected by this vulnerability?
Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 are affected.
3
What is the severity of CVE-2021-38086?
The severity of CVE-2021-38086 is high with a CVSS score of 7.8.
4
How does this vulnerability allow local privilege escalation?
This vulnerability allows local privilege escalation through DLL hijacking.
5
Is there a fix available for this vulnerability?
Yes, updating Acronis Cyber Protect 15 for Windows to build 27009 and Acronis Agent for Windows to build 26226 resolves the vulnerability.