CVE-2023-45248: High severity acronis agent vulnerability
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Agent (Windows) before build 36497.
Other sources
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36497, Acronis Cyber Protect 16 (Windows) before build 37391.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45248?
CVE-2023-45248 is a local privilege escalation vulnerability caused by DLL hijacking in Acronis Agent (Windows) before build 36497.
Which products are affected by CVE-2023-45248?
Acronis Agent (Windows) before build 36497 is affected by CVE-2023-45248.
What is the severity of CVE-2023-45248?
CVE-2023-45248 has a severity rating of 7.3 (High).
How does CVE-2023-45248 work?
CVE-2023-45248 allows local attackers to elevate their privileges by exploiting a DLL hijacking vulnerability in Acronis Agent (Windows) before build 36497.
Is Microsoft Windows vulnerable to CVE-2023-45248?
No, Microsoft Windows is not vulnerable to CVE-2023-45248.
How can I fix CVE-2023-45248?
To fix CVE-2023-45248, update Acronis Agent (Windows) to build 36497 or later.