Acronis
Acronis True Image: vulnerabilidades y CVE
Acronis True Image tiene 32 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE32
Últimos 12 meses4
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-33092 | Alta (7.8) | 0.16% | — | 10 abr 2026 | Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902. |
| CVE-2026-33271 | Media (6.7) | 0.12% | — | 2 abr 2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 42902. |
| CVE-2026-28728 | Media (6.7) | 0.13% | — | 2 abr 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902. |
| CVE-2026-27774 | Media (6.7) | 0.13% | — | 2 abr 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902. |
| CVE-2025-7779 | Alta (8.8) | 0.12% | — | 30 sept 2025 | Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42389, Acronis True Image for SanDisk (macOS) before build 42198,… |
| CVE-2025-11178 | Alta (7.3) | 0.18% | — | 30 sept 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42386, Acronis True Image for Western Digital (Windows) before build 42636,… |
| CVE-2024-55538 | Media (4) | 0.18% | — | 2 ene 2025 | Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736, Acronis True Image OEM… |
| CVE-2024-49385 | Media (5.5) | 0.15% | — | 2 ene 2025 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736, Acronis True Image OEM (Windows) before build 42575. |
| CVE-2024-34013 | Alta (7.8) | 0.64% | — | 18 jul 2024 | Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) before build 41396, Acronis True Image OEM (macOS) before build 42571. |
| CVE-2024-34010 | Alta (8.2) | 0.20% | — | 29 abr 2024 | Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758, Acronis Cyber Protect 16 (Windows) before build… |
| CVE-2022-24115 | Alta (7.8) | 0.16% | — | 4 feb 2022 | Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 (macOS) before… |
| CVE-2022-24114 | Alta (7) | 0.15% | — | 4 feb 2022 | Local privilege escalation due to race condition on application startup. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 (macOS) before build… |
| CVE-2022-24113 | Alta (7.8) | 0.21% | — | 4 feb 2022 | Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build… |
| CVE-2021-44206 | Alta (7.3) | 0.24% | — | 4 feb 2022 | Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image… |
| CVE-2021-44205 | Alta (7.3) | 0.24% | — | 4 feb 2022 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287 |
| CVE-2021-44204 | Alta (7.8) | 0.20% | — | 4 feb 2022 | Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147,… |
| CVE-2021-32581 | Alta (8.1) | 0.73% | — | 5 ago 2021 | Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis Cyber Protect prior to build 27009 did not implement SSL certificate… |
| CVE-2021-32580 | Alta (7.8) | 0.26% | — | 5 ago 2021 | Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking. |
| CVE-2021-32579 | Alta (7.8) | 0.24% | — | 5 ago 2021 | Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (who has a local code execution ability) to tamper with the micro-service… |
| CVE-2021-32578 | Alta (7.8) | 0.23% | — | 5 ago 2021 | Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 2 of 2). |
| CVE-2021-32577 | Alta (7.8) | 0.20% | — | 5 ago 2021 | Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissions. |
| CVE-2021-32576 | Alta (7.8) | 0.23% | — | 5 ago 2021 | Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2). |
| CVE-2020-25736 | Alta (7.8) | 2.2% | — | 15 jul 2021 | Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration. |
| CVE-2020-25593 | Media (6.7) | 0.25% | — | 15 jul 2021 | Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions. |
| CVE-2020-15495 | Alta (7.8) | 0.26% | — | 15 jul 2021 | Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration. |
| CVE-2020-15496 | Alta (7.8) | 0.22% | — | 15 jul 2021 | Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions. |
| CVE-2020-35145 | Alta (7.8) | 0.57% | — | 29 ene 2021 | Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components, aka an Untrusted Search Path issue. |
| CVE-2020-10140 | Alta (7.3) | 0.38% | — | 21 oct 2020 | Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code… |
| CVE-2020-10139 | Alta (7.8) | 0.43% | — | 21 oct 2020 | Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis True Image contains a privileged service that uses this OpenSSL component.… |
| CVE-2017-3219 | Alta (8.8) | 0.47% | — | 21 jun 2017 | Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.