CVE-2025-24826

CVSS 3.0 Score 6.7 of 10 (medium)

Details

Published Jan 28, 2025
CWE ID 276

Summary

CVE-2025-24826 is a local privilege escalation vulnerability that affects Acronis Snap Deploy for Windows before build 4625. The issue stems from insecure folder permissions, which can be exploited by attackers to gain elevated access to the system. Successful exploitation could result in significant damage, as the attacker would have the ability to install programs, modify data, or create new accounts with administrative privileges. Organizations using Acronis Snap Deploy are urged to update to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Acronis Snap Deploy

Affected Vendors

  • Acronis International