Junglewise Threat Intelligence

CVE-2026-42061: Acronis DeviceLock DLP local privilege escalation in child processes

CVE-2026-42061 · Severity: high · CVSS 7.3 · Published 2026-06-03

Technologies: Acronis DeviceLock DLP. Vendors: Acronis.

Executive brief

Acronis DeviceLock DLP, a security tool used to prevent data leaks from corporate endpoints, contains a vulnerability that allows a local user to gain elevated system permissions. By exploiting excessive permissions granted to child processes, an attacker with limited access can take full control of the affected Windows machine. This could lead to unauthorized data access, the bypassing of security controls, or the installation of malicious software.

Technical details

A local privilege escalation vulnerability exists in Acronis DeviceLock DLP (Windows) prior to build 9.0.15051.93227. The flaw is categorized as CWE-250 (Execution with Unnecessary Privileges) and stems from the application assigning excessive permissions to its child processes. An attacker with low-privileged local access can exploit this misconfiguration, though user interaction is required, to execute code with higher privileges (up to System). This allows for complete compromise of the confidentiality, integrity, and availability of the host. The issue is resolved in build 9.0.15051.93227.

Affected products

  • Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory

References

Related threats