All the vulnerabilites related to Acronis - Acronis True Image
cve-2025-7779
Vulnerability from cvelistv5
Published
2025-09-30 14:52
Modified
2025-09-30 15:34
Severity ?
EPSS score ?
Summary
Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42389, Acronis True Image for SanDisk (macOS) before build 42198, Acronis True Image for Western Digital (macOS) before build 42197.
References
▼ | URL | Tags |
---|---|---|
https://security-advisory.acronis.com/advisories/SEC-8193 | vendor-advisory |
Impacted products
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-7779", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T15:34:07.787991Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T15:34:50.728Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "platforms": [ "macOS" ], "product": "Acronis True Image", "vendor": "Acronis", "versions": [ { "lessThan": "42389", "status": "affected", "version": "unspecified", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "platforms": [ "macOS" ], "product": "Acronis True Image for SanDisk", "vendor": "Acronis", "versions": [ { "lessThan": "42198", "status": "affected", "version": "unspecified", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "platforms": [ "macOS" ], "product": "Acronis True Image for Western Digital", "vendor": "Acronis", "versions": [ { "lessThan": "42197", "status": "affected", "version": "unspecified", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "@nullevent (https://hackerone.com/nullevent)" }, { "lang": "en", "type": "finder", "value": "Carlos Garrido (https://pentraze.com/vulnerability-reports)" }, { "lang": "en", "type": "finder", "value": "Pentraze Cyber Security (https://pentraze.com/vulnerability-reports)" } ], "descriptions": [ { "lang": "en", "value": "Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42389, Acronis True Image for SanDisk (macOS) before build 42198, Acronis True Image for Western Digital (macOS) before build 42197." } ], "metrics": [ { "cvssV3_0": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", "version": "3.0" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-269", "description": "CWE-269", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T14:52:46.494Z", "orgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "shortName": "Acronis" }, "references": [ { "name": "SEC-8193", "tags": [ "vendor-advisory" ], "url": "https://security-advisory.acronis.com/advisories/SEC-8193" } ] } }, "cveMetadata": { "assignerOrgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "assignerShortName": "Acronis", "cveId": "CVE-2025-7779", "datePublished": "2025-09-30T14:52:46.494Z", "dateReserved": "2025-07-17T22:39:45.615Z", "dateUpdated": "2025-09-30T15:34:50.728Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2024-34013
Vulnerability from cvelistv5
Published
2024-07-18 13:36
Modified
2024-08-02 02:43
Severity ?
EPSS score ?
Summary
Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) before build 41396.
References
▼ | URL | Tags |
---|---|---|
https://security-advisory.acronis.com/advisories/SEC-7035 | vendor-advisory |
Impacted products
▼ | Vendor | Product |
---|---|---|
Acronis | Acronis True Image |
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:acronis:true_image:-:*:*:*:*:macos:*:*" ], "defaultStatus": "unknown", "product": "true_image", "vendor": "acronis", "versions": [ { "lessThan": "41396", "status": "affected", "version": "0", "versionType": "semver" } ] } ], "metrics": [ { "other": { "content": { "id": "CVE-2024-34013", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-07-18T18:00:18.497346Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-18T18:02:12.850Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T02:43:00.176Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "SEC-7035", "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://security-advisory.acronis.com/advisories/SEC-7035" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "platforms": [ "macOS" ], "product": "Acronis True Image", "vendor": "Acronis", "versions": [ { "lessThan": "41396", "status": "affected", "version": "unspecified", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "@redwise (https://hackerone.com/redwise)" } ], "descriptions": [ { "lang": "en", "value": "Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) before build 41396." } ], "metrics": [ { "cvssV3_0": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-78", "description": "CWE-78", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-07-18T13:36:39.924Z", "orgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "shortName": "Acronis" }, "references": [ { "name": "SEC-7035", "tags": [ "vendor-advisory" ], "url": "https://security-advisory.acronis.com/advisories/SEC-7035" } ] } }, "cveMetadata": { "assignerOrgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "assignerShortName": "Acronis", "cveId": "CVE-2024-34013", "datePublished": "2024-07-18T13:36:39.924Z", "dateReserved": "2024-04-29T15:33:32.845Z", "dateUpdated": "2024-08-02T02:43:00.176Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2024-34010
Vulnerability from cvelistv5
Published
2024-04-29 15:48
Modified
2025-09-30 14:53
Severity ?
EPSS score ?
Summary
Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758, Acronis Cyber Protect 16 (Windows) before build 38690, Acronis True Image (Windows) before build 42386.
References
▼ | URL | Tags |
---|---|---|
https://security-advisory.acronis.com/advisories/SEC-7110 | vendor-advisory |
Impacted products
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:acronis:cyber_protect_cloud_agent:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "cyber_protect_cloud_agent", "vendor": "acronis", "versions": [ { "lessThan": "build_37758", "status": "affected", "version": "-", "versionType": "custom" } ] } ], "metrics": [ { "other": { "content": { "id": "CVE-2024-34010", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-04-29T16:59:36.817995Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-04T17:42:35.400Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T02:42:59.932Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "SEC-7110", "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://security-advisory.acronis.com/advisories/SEC-7110" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "platforms": [ "Windows" ], "product": "Acronis Cyber Protect Cloud Agent", "vendor": "Acronis", "versions": [ { "lessThan": "37758", "status": "affected", "version": "unspecified", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "platforms": [ "Windows" ], "product": "Acronis Cyber Protect 16", "vendor": "Acronis", "versions": [ { "lessThan": "38690", "status": "affected", "version": "unspecified", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "platforms": [ "Windows" ], "product": "Acronis True Image", "vendor": "Acronis", "versions": [ { "lessThan": "42386", "status": "affected", "version": "unspecified", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "@cyberexplorer (https://hackerone.com/cyberexplorer)" } ], "descriptions": [ { "lang": "en", "value": "Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758, Acronis Cyber Protect 16 (Windows) before build 38690, Acronis True Image (Windows) before build 42386." } ], "metrics": [ { "cvssV3_0": { "baseScore": 8.2, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H", "version": "3.0" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-428", "description": "CWE-428", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T14:53:21.892Z", "orgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "shortName": "Acronis" }, "references": [ { "name": "SEC-7110", "tags": [ "vendor-advisory" ], "url": "https://security-advisory.acronis.com/advisories/SEC-7110" } ] } }, "cveMetadata": { "assignerOrgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "assignerShortName": "Acronis", "cveId": "CVE-2024-34010", "datePublished": "2024-04-29T15:48:14.398Z", "dateReserved": "2024-04-29T15:33:32.845Z", "dateUpdated": "2025-09-30T14:53:21.892Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2025-11178
Vulnerability from cvelistv5
Published
2025-09-30 14:52
Modified
2025-09-30 15:34
Severity ?
EPSS score ?
Summary
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42386.
References
▼ | URL | Tags |
---|---|---|
https://security-advisory.acronis.com/advisories/SEC-7078 | vendor-advisory |
Impacted products
▼ | Vendor | Product |
---|---|---|
Acronis | Acronis True Image |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-11178", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T15:27:47.721123Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T15:34:57.863Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "platforms": [ "Windows" ], "product": "Acronis True Image", "vendor": "Acronis", "versions": [ { "lessThan": "42386", "status": "affected", "version": "unspecified", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "@satz4797 (https://hackerone.com/satz4797)" } ], "descriptions": [ { "lang": "en", "value": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42386." } ], "metrics": [ { "cvssV3_0": { "baseScore": 7.3, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-427", "description": "CWE-427", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T14:52:20.711Z", "orgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "shortName": "Acronis" }, "references": [ { "name": "SEC-7078", "tags": [ "vendor-advisory" ], "url": "https://security-advisory.acronis.com/advisories/SEC-7078" } ] } }, "cveMetadata": { "assignerOrgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "assignerShortName": "Acronis", "cveId": "CVE-2025-11178", "datePublished": "2025-09-30T14:52:20.711Z", "dateReserved": "2025-09-29T22:35:29.171Z", "dateUpdated": "2025-09-30T15:34:57.863Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2024-55538
Vulnerability from cvelistv5
Published
2025-01-02 14:14
Modified
2025-01-02 14:49
Severity ?
EPSS score ?
Summary
Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736.
References
▼ | URL | Tags |
---|---|---|
https://security-advisory.acronis.com/advisories/SEC-2209 | vendor-advisory |
Impacted products
▼ | Vendor | Product |
---|---|---|
Acronis | Acronis True Image | |
Acronis | Acronis True Image |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2024-55538", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-01-02T14:49:50.590543Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-01-02T14:49:58.959Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "platforms": [ "macOS" ], "product": "Acronis True Image", "vendor": "Acronis", "versions": [ { "lessThan": "41725", "status": "affected", "version": "unspecified", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "platforms": [ "Windows" ], "product": "Acronis True Image", "vendor": "Acronis", "versions": [ { "lessThan": "41736", "status": "affected", "version": "unspecified", "versionType": "semver" } ] } ], "descriptions": [ { "lang": "en", "value": "Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736." } ], "metrics": [ { "cvssV3_0": { "baseScore": 4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.0" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-306", "description": "CWE-306", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-02T14:14:20.929Z", "orgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "shortName": "Acronis" }, "references": [ { "name": "SEC-2209", "tags": [ "vendor-advisory" ], "url": "https://security-advisory.acronis.com/advisories/SEC-2209" } ] } }, "cveMetadata": { "assignerOrgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "assignerShortName": "Acronis", "cveId": "CVE-2024-55538", "datePublished": "2025-01-02T14:14:20.929Z", "dateReserved": "2024-12-06T17:33:33.991Z", "dateUpdated": "2025-01-02T14:49:58.959Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2024-49385
Vulnerability from cvelistv5
Published
2025-01-02 14:14
Modified
2025-01-02 14:49
Severity ?
EPSS score ?
Summary
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736.
References
▼ | URL | Tags |
---|---|---|
https://security-advisory.acronis.com/advisories/SEC-2397 | vendor-advisory |
Impacted products
▼ | Vendor | Product |
---|---|---|
Acronis | Acronis True Image |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2024-49385", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-01-02T14:49:00.691607Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-01-02T14:49:09.334Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "platforms": [ "Windows" ], "product": "Acronis True Image", "vendor": "Acronis", "versions": [ { "lessThan": "41736", "status": "affected", "version": "unspecified", "versionType": "semver" } ] } ], "descriptions": [ { "lang": "en", "value": "Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736." } ], "metrics": [ { "cvssV3_0": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.0" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-732", "description": "CWE-732", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-02T14:14:35.360Z", "orgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "shortName": "Acronis" }, "references": [ { "name": "SEC-2397", "tags": [ "vendor-advisory" ], "url": "https://security-advisory.acronis.com/advisories/SEC-2397" } ] } }, "cveMetadata": { "assignerOrgId": "73dc0fef-1c66-4a72-9d2d-0a0f4012c175", "assignerShortName": "Acronis", "cveId": "CVE-2024-49385", "datePublished": "2025-01-02T14:14:35.360Z", "dateReserved": "2024-10-14T15:01:16.473Z", "dateUpdated": "2025-01-02T14:49:09.334Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }