CVE-2026-44609: High severity Acronis DeviceLock DLP (Windows) vulnerability
Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Acronis DeviceLock DLP (Windows)to a version that resolves this vulnerability.Fixed in 9.0.15051.93227
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44609?
CVE-2026-44609 has a severity rating of 7.3, which is categorized as high.
How does CVE-2026-44609 impact Acronis DeviceLock DLP?
CVE-2026-44609 allows local privilege escalation through EXE hijacking, affecting versions of Acronis DeviceLock DLP before build 9.0.15051.93227.
What is the risk associated with CVE-2026-44609?
CVE-2026-44609 presents a moderate risk level with a score of 64, indicating potential impact on confidentiality, integrity, and availability.
How do I fix CVE-2026-44609?
To mitigate CVE-2026-44609, update Acronis DeviceLock DLP to version 9.0.15051.93227 or later.
What type of vulnerability is CVE-2026-44609?
CVE-2026-44609 is a local privilege escalation vulnerability due to EXE hijacking.