CVE-2025-24828: Medium severity Acronis Cyber Protect Cloud Agent vulnerability
Published Jan 31, 2025
·Updated
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
Affected Software
1 affected component
Acronis Cyber Protect Cloud Agent<39378
Event History
Jan 31, 2025
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24828?
CVE-2025-24828 is classified as a high-severity local privilege escalation vulnerability.
2
How do I fix CVE-2025-24828?
To fix CVE-2025-24828, update Acronis Cyber Protect Cloud Agent to build 39378 or later.
3
What products are affected by CVE-2025-24828?
CVE-2025-24828 affects Acronis Cyber Protect Cloud Agent (Windows) versions before build 39378.
4
Can CVE-2025-24828 be exploited remotely?
CVE-2025-24828 is a local vulnerability and requires local access to exploit.
5
What type of vulnerability is CVE-2025-24828?
CVE-2025-24828 is a DLL hijacking vulnerability leading to local privilege escalation.