CVE-2024-34014

CVSS 3.0 Score 5.5 of 10 (medium)

Details

Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 61

Summary

CVE-2024-34014 is a newly disclosed vulnerability that allows an attacker to perform arbitrary file overwrites during the recovery process due to improper symbolic link handling. This issue affects several Acronis Backup products, including the plugin for cPanel & WHM (Linux) before build 818, the extension for Plesk (Linux) before build 599, and the plugin for DirectAdmin (Linux) before build 181. An attacker can exploit this vulnerability to modify or overwrite critical files, potentially leading to significant data loss or unauthorized access. It is recommended that affected users update their Acronis Backup installations as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share