CVE-2022-3405
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.
- Affected products
- Acronis, Acronis Agent, Acronis Cyber Backup 12.5, Acronis Cyber Protect 15
- Acronis Cyber Backup
- = 12.5
- Acronis Cyber Protect
- = 15
- Fix
- Available
- CVSS 3.0
- 9.3 CRITICAL
- EPSS
- 5.3% (92th percentile)
- Weakness
- CWE-269
- NVD status
- Modified
- Published
- 2023-05-03
CVE-2022-3405 at NVD
4 known exploits for CVE-2022-3405
Proof-of-concept code and exploit modules indexed by Sploitus