CVE-2022-45451

HIGH

Acronis Agent < c22.10 - Improper Privilege Management

Title source: rule
STIX 2.1

Description

Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40173, Acronis Agent (Windows) before build 30600, Acronis Cyber Protect 15 (Windows) before build 30984.

Exploits (1)

nomisec WORKING POC 18 stars
by alfarom256 · poc
https://github.com/alfarom256/CVE-2022-45451

References (2)

Core 2
Core References
Release Notes, Vendor Advisory vendor-advisory
https://security-advisory.acronis.com/advisories/SEC-4858
Release Notes, Vendor Advisory related
https://security-advisory.acronis.com/SEC-5487

Scores

CVSS v3 7.8
EPSS 0.0023
EPSS Percentile 46.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (3)
acronis/agent < c22.10
acronis/cyber_protect 15 (6 CPE variants)
acronis/cyber_protect_home_office < 40173
Published Aug 31, 2023
Tracked Since Feb 18, 2026