CVE-2025-11178
7.3Acronis · Acronis True Image
A DLL hijacking vulnerability in various Acronis True Image products allows local users to escalate their privileges on Windows systems.
Executive summary
A local privilege escalation vulnerability in multiple Acronis True Image products poses a significant risk to system integrity and security.
Vulnerability
This vulnerability is caused by insecure DLL loading (CWE-427), which allows a local attacker with standard user privileges to execute arbitrary code with elevated permissions. The attack requires local access and user interaction to trigger the hijacking process.
Business impact
Successful exploitation of this flaw allows a local, low-privileged user to gain full administrative control over the affected system. This creates a high risk of unauthorized data access, the installation of malicious software, and complete system compromise. Given the CVSS score of 7.3, this is classified as a High severity issue that requires prioritized attention to prevent lateral movement within the network.
Remediation
Immediate Action: Update the affected Acronis software to the versions specified in the vendor advisory (build 42386, 42636, 42679, or 42575 respectively) to resolve the underlying DLL loading flaw.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or the creation of unexpected files in application directories, which may indicate an attempt to perform DLL hijacking.
Compensating Controls: Implement strict file system permissions to prevent standard users from writing to application directories, effectively mitigating the ability to place malicious DLLs.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Acronis True Image on Windows platforms must prioritize patching these systems immediately to prevent local privilege escalation. Ensuring that all software is updated to the specified builds will eliminate the vulnerability and protect the system from potential administrative takeover.
More Acronis CVEs
Sources
Originally found and disclosed by @satz4797 (https://hackerone.com/satz4797), per the CVE Program record.
- SEC-7078 Vendor advisory