Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components, aka an Untrusted Search Path issue.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://www.acronis.com/en-us/products/true-image/ | product vendor advisory |
https://www.acronis.com/en-us/support/updates/changes.html?p=42246 | release notes vendor advisory |