CVE-2024-34014

UNIX Symbolic Link (Symlink) Following (CWE-61)

Published: Nov 11, 2024 / Updated: 8d ago

010
No CVSS yetEPSS 0.04%
CVE info copied to clipboard

Summary

Arbitrary file overwrite during recovery due to improper soft link handling. The vulnerability affects the following products: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup extension for Plesk (Linux) before build 599, Acronis Backup plugin for DirectAdmin (Linux) before build 181.

Impact

This vulnerability could allow an attacker to overwrite arbitrary files during the recovery process. By exploiting the improper handling of soft links, an attacker might be able to manipulate the system to overwrite critical files, potentially leading to system compromise, data loss, or unauthorized access to sensitive information.

Exploitation

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patch

Patches are available. Users should update to the following versions: - Acronis Backup plugin for cPanel & WHM (Linux): build 818 or later - Acronis Backup extension for Plesk (Linux): build 599 or later - Acronis Backup plugin for DirectAdmin (Linux): build 181 or later

Mitigation

1. Update affected Acronis Backup plugins and extensions to the latest versions as specified in the patch information. 2. If immediate updating is not possible, consider temporarily disabling or restricting access to the affected Acronis Backup components until patching can be completed. 3. Monitor system logs for any suspicious file operations, especially during recovery processes. 4. Implement the principle of least privilege for all user accounts and processes interacting with the affected software. 5. Regularly audit and validate the integrity of critical system files.

Timeline

Vendor Advisory

Acronis released a security advisory (SEC-7592).

Nov 11, 2024 at 1:00 PM
CVE Assignment

NVD published the first details for CVE-2024-34014

Nov 11, 2024 at 2:15 PM
First Article

Feedly found the first article mentioning CVE-2024-34014. See article

Nov 11, 2024 at 2:19 PM / Vulners.com RSS Feed
CVSS Estimate

Feedly estimated the CVSS score as HIGH

Nov 11, 2024 at 2:19 PM
CVSS Estimate

Feedly estimated the CVSS score as MEDIUM

Nov 11, 2024 at 2:45 PM
CVSS Estimate

Feedly estimated the CVSS score as HIGH

Nov 11, 2024 at 4:44 PM
EPSS

EPSS Score was set to: 0.04% (Percentile: 10.1%)

Nov 12, 2024 at 9:54 AM
Static CVE Timeline Graph

Affected Systems

Linux
+null more

Attack Patterns

CAPEC-27: Leveraging Race Conditions via Symbolic Links
+null more

News

CVE-2024-34014
Medium Severity Description Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup extension for Plesk (Linux) before build 599, Acronis Backup plugin for DirectAdmin (Linux) before build 181. Read more at https://www.tenable.com/cve/CVE-2024-34014
NA - CVE-2024-34014 - Arbitrary file overwrite during recovery due to...
Arbitrary file overwrite during recovery due to improper soft link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup...
CVE-2024-34014 | Acronis Backup Plugin for cPanel & WHM on Linux symlink
A vulnerability was found in Acronis Backup Plugin for cPanel & WHM, Backup Extension for Plesk and Backup Plugin for DirectAdmin on Linux. It has been rated as problematic . This issue affects some unknown processing. The manipulation leads to symlink following. The identification of this vulnerability is CVE-2024-34014 . Local access is required to approach this attack. There is no exploit available. It is recommended to upgrade the affected component.
CVE-2024-34014 - Acronis File Overwrite Vulnerability
CVE ID : CVE-2024-34014 Published : Nov. 11, 2024, 2:15 p.m. 46 minutes ago Description : Arbitrary file overwrite during recovery due to improper soft link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup extension for Plesk (Linux) before build 599, Acronis Backup plugin for DirectAdmin (Linux) before build 181. Severity:
CVE-2024-34014
Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup extension for Plesk (Linux) before build 599, Acronis Backup plugin for DirectAdmin (Linux) before build 181.
See 6 more articles and social media posts

CVSS V3.1

Unknown

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI