CVE-2025-24831 Details
Description
Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.
A local privilege escalation vulnerability has been identified in Acronis Cyber Protect Cloud Agent for Windows, prior to build 39378. This issue arises from an unquoted search path vulnerability, which can be exploited to gain elevated privileges on the system.
Users can update to Acronis Cyber Protect Cloud Agent version C25.01 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 31, 2025CISA-ADP
Assessed Apr 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security-advisory.acronis.com/advisories/SEC-6153 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Acronis Cyber Protect Cloud Agent | < 39378 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Jan 31, 2025 | CVE Modified | CISA-ADP |
| Jan 31, 2025 | New CVE Received | [email protected] |
Volerion