Local Privilege Escalation via EXE hijacking with Acronis True Image 2021 installer

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

Local Privilege Escalation via EXE hijacking with Acronis True Image 2021 installer

Post by Shane1145 »

Using the latest version of Acronis True Image 2021 (25.4.30480) is possible to perform EXE Hijacking.
This could potentially allow an authorized but privileged local user to execute arbitrary code with elevated privileges on the system.
A successful attempt would require the local attacker must insert an executable file in the path of the EXE that is called.
Upon the software installation or possibly upgrade, the malicious code will be run with elevated privileges.


https://hackerone.com/reports/970739
Post Reply