漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
N/A
漏洞信息
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to quarantine files by copying a suspected ransomware file from one directory to another using SYSTEM privileges. Because unprivileged users have write permissions in the quarantine folder, it is possible to control this privileged write with a hardlink. This means that an unprivileged user can write/overwrite arbitrary files in arbitrary folders. Escalating privileges to SYSTEM is trivial with arbitrary writes. While the quarantine feature is not enabled by default, it can be forced to copy the file to the quarantine by communicating with anti_ransomware_service.exe through its REST API.
漏洞信息
N/A
漏洞
N/A
漏洞
Acronis True Image 后置链接漏洞
漏洞信息
Acronis True Image是新加坡安克诺斯(Acronis)的一款著名的数据备份还原软件。该软件可用于创建驱动器和磁盘映像,并在需要干净系统时可以还原镜像。 Acronis True Image 2020 24.5.22510版本存在安全漏洞,该漏洞源于程序包含通过使用SYSTEM权限将可疑的勒索软件文件从一个目录复制到另一个目录来隔离文件的功能。由于非特权用户在隔离文件夹中具有写权限,因此可以使用硬链接控制这种特权写。这意味着无特权用户可以写覆盖任意文件夹中的任意文件。
漏洞信息
N/A
漏洞
N/A