{ "schema_version": "1.4.0", "id": "GHSA-p2rm-4jg3-5463", "modified": "2022-05-24T19:03:14Z", "published": "2022-05-24T19:03:14Z", "aliases": [ "CVE-2020-9450" ], "details": "An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe exposes a REST API that can be used by everyone, even unprivileged users. This API is used to communicate from the GUI to anti_ransomware_service.exe. This can be exploited to add an arbitrary malicious executable to the whitelist, or even exclude an entire drive from being monitored by anti_ransomware_service.exe.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9450" }, { "type": "WEB", "url": "https://danishcyberdefence.dk/blog" }, { "type": "WEB", "url": "https://madsjoensen.dk/cve-2020-9450" }, { "type": "WEB", "url": "https://www.acronis.com" } ], "database_specific": { "cwe_ids": [ "CWE-276" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-05-25T12:15:00Z" } }