CVE-2025-9578
7.8Acronis · Cyber Protect Cloud Agent
A local privilege escalation vulnerability exists in Acronis Cyber Protect Cloud Agent for Windows due to insecure folder permissions, allowing local users to gain elevated system privileges.
Executive summary
A vulnerability in the Acronis Cyber Protect Cloud Agent for Windows permits local privilege escalation, posing a significant risk to system integrity and security.
Vulnerability
This vulnerability, categorized as CWE-732 (Incorrect Permission Assignment for Critical Resource), arises from insecure folder permissions. An authenticated local user can exploit these weak permissions to achieve unauthorized privilege escalation on the host system.
Business impact
The ability for a local user to escalate privileges to a higher level, such as system administrator, creates a severe security risk. This could lead to full system compromise, unauthorized data access, and the potential for attackers to bypass security controls. With a CVSS score of 7.8, this vulnerability is classified as High severity and requires prompt attention to prevent lateral movement or total machine takeover.
Remediation
Immediate Action: Update the Acronis Cyber Protect Cloud Agent for Windows to build 40734 or later immediately.
Proactive Monitoring: Review system logs for unusual process execution or unauthorized changes to sensitive system files and directory permissions.
Compensating Controls: Restrict local user access to the directory structures where the Acronis agent is installed to prevent non-privileged users from interacting with the vulnerable components.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete system compromise via privilege escalation, organizations must prioritize the deployment of the vendor-supplied update to build 40734. Administrators should verify the version of the agent across all Windows endpoints and ensure that security patches are applied without delay to mitigate this high-severity risk.
More Acronis CVEs
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
- Fix documented version 40734 per CVE record
Sources
Originally found and disclosed by @wdormann (https://hackerone.com/wdormann), per the CVE Program record.
- SEC-9107 Vendor advisory