CVE-2025-30408

CVSS 3.0 Score 6.7 of 10 (medium)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 732

Summary

CVE-2025-30408 is a local privilege escalation vulnerability that affects the Acronis Cyber Protect Cloud Agent for Windows before build 39904. This issue arises due to insecure folder permissions, which could allow an attacker to gain elevated privileges on a vulnerable system. An attacker could exploit this vulnerability to escalate their privileges and potentially gain unauthorized access to sensitive data or make unauthorized changes to the system. Organizations using the affected Acronis product are strongly advised to apply the available patch as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Acronis Cyber Protect Cloud Agent

Affected Vendors

  • Acronis International