Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://security-advisory.acronis.com/advisories/SEC-4540 | vendor advisory |