CVE detail
CVE-2020-9450 — CVE-2020-9450
Published 2021-05-25 · Modified 2026-06-17 · Vendor acronis · Product true_image_2020 · Source nvd
HIGH
severity
CVSS-derived band
0.0040
EPSS probability
exploitation probability, 30d
32.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe exposes a REST API that can be used by everyone, even unprivileged users. This API is used to communicate from the GUI to anti_ransomware_service.exe. This can be exploited to add an arbitrary malicious executable to the whitelist, or even exclude an entire drive from being monitored by anti_ransomware_service.exe.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References