CVE-2025-9578: High severity Acronis Cyber Protect Cloud Agent vulnerability
Published Aug 28, 2025
·Updated
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 40734.
Affected Software
1 affected component
Acronis Cyber Protect Cloud Agent<40734
Event History
Aug 28, 2025
CVE Published
via MITRE·02:01 PM
Data Sourced
via MITRE·02:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Feb 28, 57989
Event
via FIRST·05:58 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9578?
CVE-2025-9578 has a high severity rating due to its potential for local privilege escalation.
2
How do I fix CVE-2025-9578?
To fix CVE-2025-9578, upgrade to Acronis Cyber Protect Cloud Agent version 40734 or later.
3
What products are affected by CVE-2025-9578?
Acronis Cyber Protect Cloud Agent (Windows) versions before build 40734 are affected by CVE-2025-9578.
4
What does CVE-2025-9578 exploit?
CVE-2025-9578 exploits insecure folder permissions to escalate local privileges.
5
Who is the vendor for CVE-2025-9578?
The vendor for CVE-2025-9578 is Acronis.