Lucene search

K
cvelistCertccCVELIST:CVE-2020-10140
HistoryOct 21, 2020 - 1:40 p.m.

CVE-2020-10140

2020-10-2113:40:19
CWE-732
certcc
www.cve.org
7
acronis
true image
acls
vulnerability
arbitrary code execution
privileged processes

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

10.4%

Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileges by placing a DLL in one of several paths within C:\ProgramData\Acronis.

CNA Affected

[
  {
    "product": "True Image",
    "vendor": "Acronis",
    "versions": [
      {
        "lessThan": "32010",
        "status": "affected",
        "version": "2021",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

10.4%

Related for CVELIST:CVE-2020-10140