CVE-2021-44198: DLL hijacking could lead to local privilege escalation
Published Nov 29, 2021
·Updated
DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035
Affected Software
10 affected components
All of the following
Any of the following
Acronis Cyber Protect<15
Acronis Cyber Protect=15
Acronis Cyber Protect=15-update1
Acronis Cyber Protect=15-update2
Microsoft Windows
Acronis Cyber Protect<15
Acronis Cyber Protect=15
Acronis Cyber Protect=15-update1
Acronis Cyber Protect=15-update2
Microsoft Windows
Remediation
Patch Available
Event History
Nov 29, 2021
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this DLL hijacking vulnerability?
The vulnerability ID for this DLL hijacking vulnerability is CVE-2021-44198.
2
What is the severity of CVE-2021-44198?
The severity of CVE-2021-44198 is high (7.8).
3
Which products are affected by CVE-2021-44198?
The following products are affected by CVE-2021-44198: Acronis Cyber Protect 15 (Windows) before build 28035.
4
How can this vulnerability lead to local privilege escalation?
This vulnerability allows an attacker to load a malicious DLL file instead of a legitimate one, which could lead to the execution of arbitrary code with elevated privileges.
5
How do I fix CVE-2021-44198?
To fix CVE-2021-44198, it is recommended to upgrade to Acronis Cyber Protect 15 (Windows) build 28035 or later.