Executive brief
Acronis DeviceLock DLP, a security solution used to prevent data leaks from corporate endpoints, is vulnerable to a local privilege escalation flaw. An attacker with existing low-level access to a Windows machine could exploit this to gain full administrative control over the system. This could allow an unauthorized user to bypass security policies, access sensitive data, or disable protective measures.
Technical details
A local privilege escalation vulnerability exists in Acronis DeviceLock DLP (Windows) due to an uncontrolled search path (CWE-427), commonly known as DLL hijacking. The application fails to properly validate or restrict the search path used to load dynamic link libraries, allowing a local attacker with low privileges to place a malicious DLL in a location where it will be executed by a higher-privileged process. Successful exploitation requires minimal user interaction and allows the attacker to achieve full system compromise (High Confidentiality, Integrity, and Availability impact). The issue is resolved in build 9.0.15051.93227.
Affected products
- Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory