CVE-2025-30408
CVSS 3.0 Score 6.7 of 10 (medium)
Details
Summary
CVE-2025-30408 is a local privilege escalation vulnerability that affects the Acronis Cyber Protect Cloud Agent for Windows before build 39904. This issue arises due to insecure folder permissions, which could allow an attacker to gain elevated privileges on a vulnerable system. An attacker could exploit this vulnerability to escalate their privileges and potentially gain unauthorized access to sensitive data or make unauthorized changes to the system. Organizations using the affected Acronis product are strongly advised to apply the available patch as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Acronis Cyber Protect Cloud Agent
Affected Vendors
- Acronis International