Executive brief
Acronis security and data loss prevention software for Windows contains a vulnerability that allows a user with low-level access to gain full administrative control over the system. This could allow an attacker who has already gained a foothold on a computer to bypass security restrictions, access sensitive data, or disable protection services. Organizations should update their Acronis agents to the latest builds to prevent local privilege escalation.
Technical details
A local privilege escalation vulnerability exists in Acronis DeviceLock DLP and Cyber Protect Cloud Agent for Windows due to improper input validation. The root cause is identified as an out-of-bounds write (CWE-787) within the affected components. An attacker with local access and low-level privileges can exploit this flaw to execute code with higher privileges, potentially reaching SYSTEM level. The vulnerability is addressed in DeviceLock DLP build 9.0.93212 and Cyber Protect Cloud Agent build 42183. No user interaction is required for exploitation once local access is established.
Affected products
- Acronis DeviceLock DLP (Windows) before build 9.0.93212
- Acronis Cyber Protect Cloud Agent (Windows) before build 42183
Timeline
- 2026-04-29: disclosed: Initial advisory publication
- 2026-04-29: advisory: NVD record published