Executive brief
Acronis DeviceLock DLP, a security tool used to prevent data leaks on corporate endpoints, is vulnerable to a local privilege escalation flaw. An attacker with limited access to a computer could trick the software into running a malicious file, allowing them to gain full administrative control over the system. This could lead to the bypass of security policies, theft of sensitive data, or the installation of persistent malware.
Technical details
A local privilege escalation vulnerability exists in Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227 due to an uncontrolled search path (CWE-427), commonly referred to as EXE hijacking. The application fails to properly validate or restrict the search path used to locate and execute binary files. A local attacker with low-level privileges can exploit this by placing a malicious executable in a directory that the application searches before the legitimate binary's location. Successful exploitation requires some user interaction and allows the attacker to execute arbitrary code with the elevated privileges of the DeviceLock service or application.
Affected products
- Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory