CVE Vulnerabilities

CVE-2022-45455

Incomplete Cleanup

Published: Feb 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107, Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

NameVendorStart VersionEnd Version
AgentAcronis*c22.07 (excluding)
Cyber_protectAcronis15 (including)15 (including)
Cyber_protectAcronis15-update1 (including)15-update1 (including)
Cyber_protectAcronis15-update2 (including)15-update2 (including)
Cyber_protectAcronis15-update3 (including)15-update3 (including)
Cyber_protectAcronis15-update4 (including)15-update4 (including)
Cyber_protect_home_officeAcronis- (including)- (including)

Potential Mitigations

References