Executive brief
Acronis True Image, a popular backup and data protection software, is vulnerable to a security flaw that could allow a local user to gain higher-level system permissions. By placing a malicious file on the computer, an attacker could trick the software into running unauthorized code with elevated privileges. This could lead to full control over the affected system and its stored backups.
Technical details
A DLL hijacking vulnerability (CWE-427: Uncontrolled Search Path Element) exists in Acronis True Image for Windows before build 42902. The application fails to properly validate or restrict the search path used to load dynamic link libraries (DLLs), allowing a local attacker with low privileges to place a malicious DLL in a location searched by the application. If a user with higher privileges or a system process triggers the application, the malicious code is executed with those elevated permissions. Exploitation requires local access and some degree of user interaction or specific environmental conditions (AC:H). The issue is resolved in build 42902.
Affected products
- Acronis True Image (Windows) before build 42902
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory