Acronis warns of actively exploited flaw in its cPanel backup plugin

Summary

Acronis has disclosed a critical vulnerability in its cPanel backup plugin that could allow attackers to escalate privileges on Linux systems. The flaw is reportedly being actively exploited in the wild.

IFF Assessment

FOE

The active exploitation of a privilege escalation vulnerability presents a direct threat to systems and data, making it bad news for defenders.

Severity

8.8 High (AI Estimated)

This vulnerability is estimated to have a high CVSS score due to its potential for local privilege escalation, allowing an attacker to gain elevated access on a compromised system. The 'exploited in the wild' status further indicates a high likelihood of successful attacks.

Defender Context

Defenders need to prioritize patching or mitigating this vulnerability in Acronis backup plugins for cPanel, WHM, and Plesk to prevent unauthorized privilege escalation. Monitoring systems for signs of compromise and ensuring robust backup security practices are essential.

Read Full Story →