By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Acronis Warns of Exploited Flaw in cPanel Backup Plugin
Acronis, a cybersecurity company specializing in data protection and disaster recovery, has issued a warning regarding a critical vulnerability present in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk. This vulnerability, identified as a Linux local privilege escalation flaw, is reportedly being actively exploited in the wild. The company disclosed the issue on March 14, 2024, in a security advisory, urging users to update their software immediately to mitigate the risk. The flaw, tracked as CVE-2024-29821, allows an unauthenticated attacker with local access to gain root privileges on the affected server. This means an attacker could potentially take complete control of the server, access sensitive data, install malware, or disrupt services. The vulnerability specifically impacts the Acronis Cyber Protect Cloud backup plugin for cPanel/WHM and Acronis Cyber Protect for cPanel, affecting versions prior to 3.0.1. The company has released version 3.0.1 of the plugin, which addresses this critical security gap. Acronis has not disclosed the exact number of affected customers or the extent of the exploitation, but its advisory emphasizes the high severity and the active exploitation in the wild, indicating that attackers are already leveraging this weakness. The cPanel and WHM platforms are widely used by web hosting providers to manage websites and servers, making this vulnerability a significant concern for the hosting industry and the businesses that rely on these services. Acronis recommends that all users of the affected plugins verify their installed version and upgrade to version 3.0.1 or later as soon as possible. For users who cannot immediately upgrade, Acronis suggests disabling the plugin as a temporary workaround. The company's proactive disclosure and rapid release of a patch underscore the ongoing challenges in securing complex software ecosystems, particularly those used in critical infrastructure like web hosting. This incident highlights the importance of regular security audits and prompt patching of vulnerabilities, especially for software that handles sensitive data backups and server management. The potential for root-level access means that compromised servers could be used for a variety of malicious activities, including launching further attacks, distributing spam, or hosting phishing sites. The advisory also notes that the vulnerability was discovered internally by Acronis's security team, though it does not provide details on how the exploitation is occurring. The urgency of the advisory suggests that the exploitation is relatively straightforward, increasing the risk for unpatched systems. Acronis is a global leader in cyber protection, offering solutions that combine data protection, cybersecurity, and endpoint management. Its products are used by millions of consumers and hundreds of thousands of businesses worldwide. The cPanel and WHM platforms are control panel software used to simplify website and server management, making them a common target for attackers seeking to compromise hosting environments. The vulnerability's presence in a backup plugin is particularly concerning, as these plugins often have elevated privileges to perform their functions, making them attractive targets for privilege escalation attacks.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.