CVE-2020-10140 is a privilege escalation vulnerability in Acronis True Image 2021, stemming from improperly set Access Control Lists (ACLs) on the C:\ProgramData\Acronis directory. This allows an unprivileged local user to achieve arbitrary code execution with SYSTEM privileges by placing a malicious DLL in specific paths within that directory, which is then executed by privileged processes. The vulnerability has a CVSS score of 7.3 (HIGH), indicating a low attack complexity and requiring user interaction for exploitation, with high impacts on confidentiality, integrity, and availability. While there are no public exploit modules or evidence of active exploitation, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2021CPE matchmatch criteria | cpe:2.3:a:acronis:true_image:2021:*:*:*:*:*:*:* | ||
>= 2021, < 32010CPE match | cpe:2.3:a:acronis:true_image:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.