CVE-2023-41743: High severity Acronis Agent vulnerability
Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis Agent (Windows) before build 31637, Acronis Cyber Protect 15 (Windows) before build 35979.
Other sources
Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis Cyber Protect Cloud Agent (Windows) before build 31637, Acronis Cyber Protect 15 (Windows) before build 35979, Acronis True Image OEM (Windows) before build 42575.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-41743.
What is the severity level of CVE-2023-41743?
The severity level of CVE-2023-41743 is high with a CVSS score of 7.8.
Which products are affected by CVE-2023-41743?
The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis Agent (Windows) before build 31637, Acronis Cyber Protect 15 (Windows) before build 35979.
How can I fix CVE-2023-41743?
To fix CVE-2023-41743, update Acronis Cyber Protect Home Office to build 40278, Acronis Agent to build 31637, and Acronis Cyber Protect 15 to build 35979.
Where can I find more information about CVE-2023-41743?
You can find more information about CVE-2023-41743 at the following references: [Link to Acronis security advisory 1](https://security-advisory.acronis.com/SEC-4858) and [Link to Acronis security advisory 2](https://security-advisory.acronis.com/advisories/SEC-5487).