CVE-2022-46869 describes a local privilege escalation vulnerability in Acronis Cyber Protect Home Office (Windows) before build 40278, stemming from improper soft link handling during installation. This high-severity flaw (CVSS 7.8) allows a low-privileged local attacker to gain full control over the affected system with low attack complexity and no user interaction. While the vulnerability has a low EPSS score and no known active exploitation, public exploit code, or significant community discussion, its potential for complete system compromise warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 40278CPE matchmatch criteria | cpe:2.3:a:acronis:cyber_protect_home_office:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.