CVE-2024-8766: Medium severity acronis cyber protect cloud agent vulnerability
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235, Acronis Cyber Protect 16 (Windows) before build 39169.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8766?
CVE-2024-8766 is classified as a high severity local privilege escalation vulnerability.
How do I fix CVE-2024-8766?
To resolve CVE-2024-8766, update Acronis Cyber Protect Cloud Agent to build 38235 or later, and Acronis Cyber Protect 16 to build 39169 or later.
What products are affected by CVE-2024-8766?
The affected products for CVE-2024-8766 include Acronis Cyber Protect Cloud Agent before build 38235 and Acronis Cyber Protect 16 before build 39169.
Can CVE-2024-8766 be exploited remotely?
CVE-2024-8766 requires local access to exploit, making it a local privilege escalation vulnerability rather than a remote one.
What is DLL hijacking in the context of CVE-2024-8766?
In CVE-2024-8766, DLL hijacking refers to the ability of an attacker to exploit the way Windows loads dynamic link libraries, potentially gaining higher privileges on the system.