CVE-2024-55540: High severity acronis cyber protect 16 vulnerability
Published Jan 2, 2025
·Updated
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
Affected Software
6 affected components
Acronis Cyber Protect 16<build 39169
All of the following
Any of the following
Acronis Cyber Protect<=15
Acronis Cyber Protect=16
Acronis Cyber Protect=16-update1
Acronis Cyber Protect=16-update2
Microsoft Windows
Event History
Jan 2, 2025
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55540?
CVE-2024-55540 is classified as a high severity local privilege escalation vulnerability.
2
How do I fix CVE-2024-55540?
To fix CVE-2024-55540, update Acronis Cyber Protect 16 to build 39169 or later.
3
What products are affected by CVE-2024-55540?
CVE-2024-55540 affects Acronis Cyber Protect 16 on Windows versions prior to build 39169.
4
Can CVE-2024-55540 be exploited remotely?
CVE-2024-55540 requires local access to the affected system to exploit the DLL hijacking vulnerability.
5
What is a DLL hijacking vulnerability like CVE-2024-55540?
A DLL hijacking vulnerability like CVE-2024-55540 allows an attacker to execute malicious code with elevated privileges by tricking the application into loading a compromised DLL.