CVE-2025-30408: Medium severity Acronis Cyber Protect Cloud Agent vulnerability
Published Apr 24, 2025
·Updated
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904, Acronis Cyber Protect 16 (Windows) before build 39938.
Affected Software
2 affected components
Acronis Cyber Protect Cloud Agent<39904
Acronis Cyber Protect 16<39938
Event History
Apr 24, 2025
CVE Published
via MITRE·01:04 PM
Data Sourced
via MITRE·01:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-30408?
CVE-2025-30408 is classified as a high severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2025-30408?
To fix CVE-2025-30408, ensure that you update Acronis Cyber Protect Cloud Agent to build 39904 or later.
3
What products are affected by CVE-2025-30408?
CVE-2025-30408 affects the Acronis Cyber Protect Cloud Agent (Windows) prior to build 39904.
4
How does CVE-2025-30408 work?
CVE-2025-30408 exploits insecure folder permissions, allowing unauthorized users to gain elevated privileges on the system.
5
Is CVE-2025-30408 exploitable remotely?
No, CVE-2025-30408 requires local access to the system to be exploited.