CVE-2024-56413

CVSS 3.0 Score 6.1 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 613

Summary

CVE-2024-56413 is a newly disclosed vulnerability affecting Acronis Cyber Protect 16 for Windows, with versions prior to build 39169 being impacted. This issue arises due to a missing session invalidation mechanism following user deletion. An attacker who gains unauthorized access to a deleted user account could potentially maintain persistence on the targeted system, posing a significant risk to data confidentiality and integrity. Organizations using the affected software are advised to apply the latest patch or update as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share