Junglewise Threat Intelligence

CVE-2026-25852: Acronis DeviceLock DLP privilege escalation via DLL hijacking

CVE-2026-25852 · Severity: medium · CVSS 6.7 · Published 2026-04-29

Technologies: Acronis DeviceLock DLP. Vendors: Acronis.

Executive brief

Acronis DeviceLock DLP, a security solution used to prevent data leaks from corporate endpoints, is vulnerable to a local privilege escalation flaw. An attacker who already has limited access to a Windows computer could exploit this to gain full administrative control over the system. This could allow them to bypass security controls, access sensitive data, or disrupt business operations.

Technical details

A DLL hijacking vulnerability (CWE-427: Uncontrolled Search Path Element) exists in Acronis DeviceLock DLP for Windows before build 9.0.93212. The application fails to properly validate or restrict the search path used to load dynamic link libraries (DLLs). A local attacker with low privileges can exploit this by placing a malicious DLL in a directory searched by the application, which is then executed with the higher privileges of the DeviceLock service or process. Successful exploitation requires some user interaction and specific environmental conditions (AC:H), ultimately allowing the attacker to achieve full system compromise. The issue is resolved in build 9.0.93212.

Affected products

  • Acronis DeviceLock DLP (Windows) before build 9.0.93212

Timeline

  • 2026-04-29: disclosed
  • 2026-04-29: advisory

References

Related threats