First published: Mon Nov 11 2024(Updated: )
Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.6.599, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.2.181.
Credit: security@acronis.com
Affected Software | Affected Version | How to fix |
---|---|---|
Acronis Backup plugin for cPanel & WHM (Linux) | <1.8.3.818 | |
Acronis Backup plugin for cPanel & WHM (Linux) | <1.9.1.892 | |
Acronis Backup extension for Plesk (Linux) | <1.8.6.599 | |
Acronis Backup plugin for DirectAdmin (Linux) | <1.2.2.181 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34014 is considered to have a critical severity due to the potential for arbitrary file overwrite.
To fix CVE-2024-34014, update Acronis Backup plugins and extensions to the latest builds: 818 for cPanel & WHM, 599 for Plesk, and 181 for DirectAdmin.
CVE-2024-34014 affects Acronis Backup plugin for cPanel & WHM, Acronis Backup extension for Plesk, and Acronis Backup plugin for DirectAdmin versions prior to specified builds.
Exploitation of CVE-2024-34014 could allow attackers to overwrite arbitrary files on the affected systems.
Currently, there are no known workarounds for CVE-2024-34014, so immediate updates are recommended.