VYPR

Vendor CVEs

Acronis

All CVEs

218 total · sorted by risk
  • CVE-2022-24113HigFeb 4, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build…

  • CVE-2021-44204HigFeb 4, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build…

  • CVE-2021-44198HigNov 29, 2021
    risk 0.51cvss 7.8epss 0.00

    DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035

  • CVE-2021-38088HigAug 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.

  • CVE-2021-38086HigAug 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.

  • CVE-2021-32580HigAug 5, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking.

  • CVE-2021-32579HigAug 5, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (who has a local code execution ability) to tamper with the micro-service API.

  • CVE-2021-32578HigAug 5, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 2 of 2).

  • CVE-2021-32577HigAug 5, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissions.

  • CVE-2021-32576HigAug 5, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2).

  • CVE-2020-15495HigJul 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration.

  • CVE-2020-15496HigJul 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.

  • CVE-2020-9452HigMay 25, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to quarantine files by copying a suspected ransomware file from one directory to another using SYSTEM privileges. Because unprivileged users have write permissions…

  • CVE-2020-9450HigMay 25, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe exposes a REST API that can be used by everyone, even unprivileged users. This API is used to communicate from the GUI to anti_ransomware_service.exe. This can be exploited to add an…

  • CVE-2020-35145HigJan 29, 2021
    risk 0.51cvss 7.8epss 0.01

    Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components, aka an Untrusted Search Path issue.

  • CVE-2020-10140HigOct 21, 2020
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileges by placing a DLL in one of…

  • CVE-2020-10139HigOct 21, 2020
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis True Image contains a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories…

  • CVE-2020-10138HigOct 21, 2020
    risk 0.51cvss 7.8epss 0.01

    Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis Cyber Backup and Cyber Protect contain a privileged service that uses this OpenSSL component. Because…

  • CVE-2026-28718HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Denial of service due to insufficient input validation in authentication logging. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2025-30415HigJun 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Denial of service due to improper handling of malformed input. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40077, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

  • CVE-2024-49387HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.00

    Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2023-44159HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2023-44158HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2023-44156HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2023-44155HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2023-44153HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2023-5042HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.

  • CVE-2023-41749HigAug 31, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Windows) before build 32047, Acronis Cyber Protect 15 (Windows) before build 35979.

  • CVE-2023-41742HigAug 31, 2023
    risk 0.49cvss 7.5epss 0.00

    Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2022-45459HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.

  • CVE-2022-45458HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984.

  • CVE-2022-45457HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984.

  • CVE-2022-45453HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.

  • CVE-2022-45450HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 30984.

  • CVE-2023-2360HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.

  • CVE-2022-45456HigApr 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161.

  • CVE-2022-45454HigFeb 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161, Acronis Cyber Protect 15 (Windows) before build 30984.

  • CVE-2022-30994HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240

  • CVE-2022-30993HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

  • CVE-2022-30990HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before build 29240, Acronis Agent (Linux) before build 28037

  • CVE-2021-34800HigNov 29, 2021
    risk 0.49cvss 7.5epss 0.01

    Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147

  • CVE-2020-14999HigJul 30, 2021
    risk 0.49cvss 7.5epss 0.01

    A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Windows memory protection and access sensitive data.

  • CVE-2020-35556HigFeb 22, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.

  • CVE-2026-50033HigJun 3, 2026
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

  • CVE-2026-44682HigJun 3, 2026
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

  • CVE-2026-44609HigJun 3, 2026
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

  • CVE-2026-42061HigJun 3, 2026
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

  • CVE-2026-28722HigMar 6, 2026
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

  • CVE-2026-28721HigMar 6, 2026
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

  • CVE-2025-11792HigMar 6, 2026
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 41124.

Page 2 of 5