Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-44609

CVE-2026-44609: Acronis DeviceLock DLP Privilege Escalation

CVE-2026-44609 is a privilege escalation vulnerability in Acronis DeviceLock DLP caused by EXE hijacking. Attackers can exploit this to gain elevated system privileges. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-44609 Overview

CVE-2026-44609 is a local privilege escalation vulnerability in Acronis DeviceLock DLP for Windows. The flaw allows a low-privileged local user to hijack executable loading behavior and run code in the context of a higher-privileged process. The issue is tracked under CWE-427: Uncontrolled Search Path Element and affects Acronis DeviceLock DLP (Windows) builds before 9.0.15051.93227.

Critical Impact

A local attacker with low privileges can escalate to higher privileges on Windows endpoints running vulnerable Acronis DeviceLock DLP builds, compromising confidentiality, integrity, and availability.

Affected Products

  • Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227

Discovery Timeline

  • 2026-06-03 - CVE CVE-2026-44609 published to NVD
  • 2026-06-03 - Last updated in NVD database

Technical Details for CVE-2026-44609

Vulnerability Analysis

The vulnerability is an EXE hijacking flaw in Acronis DeviceLock DLP on Windows. The product invokes an executable from a location or with a search order that a low-privileged user can influence. A local attacker plants a malicious binary in a path that the DLP service or its components resolve before the legitimate executable. When the higher-privileged process launches, Windows loads the attacker-controlled binary in place of the intended one.

Exploitation requires local access and user interaction, as reflected in the attack vector. The successful outcome is execution of arbitrary code under the privileges of the DeviceLock DLP component, enabling privilege escalation on the host. Endpoint Data Loss Prevention (DLP) agents typically run with elevated rights to enforce policy, which makes such hijacks an effective path to SYSTEM-level control.

Root Cause

The root cause is an uncontrolled search path element [CWE-427]. The application does not enforce a fully qualified path or integrity check on a target executable, allowing resolution to a location writable by a non-administrative user. Standard Windows behavior then loads the planted binary at launch.

Attack Vector

An attacker with local, low-privileged access drops a malicious executable into a directory consulted by DeviceLock DLP during process startup. When a privileged DeviceLock DLP operation runs the targeted executable, the attacker's code executes in that elevated context. Technical specifics are described in Acronis Security Advisory SEC-3084.

Detection Methods for CVE-2026-44609

Indicators of Compromise

  • Unexpected executable files written to directories used by Acronis DeviceLock DLP or adjacent to its install path by non-administrative users.
  • Child processes spawned by DeviceLock DLP service binaries that do not match the vendor's signed executables.
  • Anomalous file modifications under user-writable directories that resolve in the Windows executable search order.

Detection Strategies

  • Monitor process creation events where the parent is a DeviceLock DLP component and the child binary is unsigned or signed by a non-Acronis publisher.
  • Alert on writes of .exe files to directories referenced by DeviceLock DLP processes, especially by standard users.
  • Compare loaded executable paths against an allowlist of expected, fully qualified Acronis installation paths.

Monitoring Recommendations

  • Enable Windows process creation auditing (Event ID 4688) with command line logging on endpoints running DeviceLock DLP.
  • Forward endpoint telemetry to a centralized analytics platform and correlate file write, process creation, and signature validation events.
  • Track DeviceLock DLP service restarts and unexpected privilege changes on protected hosts.

How to Mitigate CVE-2026-44609

Immediate Actions Required

  • Upgrade Acronis DeviceLock DLP (Windows) to build 9.0.15051.93227 or later on all affected endpoints.
  • Inventory hosts running vulnerable builds and prioritize systems where standard users have interactive logon rights.
  • Audit directories in the executable search path for write permissions granted to non-administrative users.

Patch Information

Acronis has released a fixed build of DeviceLock DLP for Windows. Apply build 9.0.15051.93227 or later as described in Acronis Security Advisory SEC-3084.

Workarounds

  • Restrict interactive local logon on endpoints running DeviceLock DLP to trusted administrative accounts.
  • Remove write permissions for standard users on directories that resolve in the Windows executable search order for DeviceLock DLP processes.
  • Enforce application control policies, such as Windows Defender Application Control or AppLocker, to allow only signed Acronis binaries to execute from approved paths.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.