CVE-2021-38086

Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.
References
Link Resource
https://kb.acronis.com/content/68564 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*
cpe:2.3:a:acronis:cyber_protect:15:-:*:*:*:*:*:*
cpe:2.3:a:acronis:cyber_protect:15:update1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

23 Sep 2021, 13:48

Type Values Removed Values Added
CPE cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:windows:*:*
cpe:2.3:a:acronis:cyber_protect:15:-:*:*:*:windows:*:*
cpe:2.3:a:acronis:cyber_protect:15:update1:*:*:*:windows:*:*
cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*
cpe:2.3:a:acronis:cyber_protect:15:-:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:acronis:cyber_protect:15:update1:*:*:*:*:*:*

20 Aug 2021, 19:48

Type Values Removed Values Added
CWE CWE-427
CVSS v2 : unknown
v3 : unknown
v2 : 4.4
v3 : 7.8
CPE cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:windows:*:*
cpe:2.3:a:acronis:cyber_protect:15:-:*:*:*:windows:*:*
cpe:2.3:a:acronis:cyber_protect:15:update1:*:*:*:windows:*:*
References (MISC) https://kb.acronis.com/content/68564 - (MISC) https://kb.acronis.com/content/68564 - Vendor Advisory

12 Aug 2021, 15:08

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-12 14:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-38086

Mitre link : CVE-2021-38086

CVE.ORG link : CVE-2021-38086


JSON object : View

Products Affected

acronis

  • cyber_protect

microsoft

  • windows
CWE
CWE-427

Uncontrolled Search Path Element