CVE-2025-24830

CVSS 3.0 Score 6.3 of 10 (medium)

Details

Published Jan 31, 2025
Updated: Feb 18, 2025
CWE ID 426

Summary

CVE-2025-24830 is a local privilege escalation vulnerability that arises due to a DLL hijacking issue. This weakness affects the Acronis Cyber Protect Cloud Agent for Windows, with versions before build 39378 being vulnerable. An attacker who successfully exploits this vulnerability gains elevated system privileges, potentially leading to serious security consequences. The DLL hijacking vulnerability enables an attacker to replace a legitimate DLL with a malicious one, allowing for unauthorized code execution with heightened privileges. Organizations using the Acronis Cyber Protect Cloud Agent on Windows systems should promptly update to the latest build to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share