CVE-2025-48959: Medium severity Acronis Cyber Protect Cloud Agent vulnerability
Published Jun 4, 2025
·Updated
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 40077.
Affected Software
1 affected component
Acronis Cyber Protect Cloud Agent<40077
Event History
Jun 4, 2025
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-48959?
CVE-2025-48959 is classified as a high-severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2025-48959?
To mitigate CVE-2025-48959, update Acronis Cyber Protect Cloud Agent to build 40077 or later.
3
Which products are affected by CVE-2025-48959?
CVE-2025-48959 affects Acronis Cyber Protect Cloud Agent (Windows) versions before build 40077.
4
What type of vulnerability is CVE-2025-48959?
CVE-2025-48959 is a local privilege escalation vulnerability caused by insecure file permissions.
5
Is there a way to detect if CVE-2025-48959 is being exploited?
Monitoring system logs for unusual behavior and unauthorized access attempts can help detect exploitation of CVE-2025-48959.