PT-2026-27472 · Idrive · I-Drive

Matthew Owens

·

Publicado

2026-03-24

·

Atualizado

2026-05-04

·

CVE-2026-1995

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IDrive versions (affected versions not specified)
Description The id service.exe process operates with elevated privileges and routinely reads files located in the C:ProgramDataIDrive directory. These files, encoded in UTF16-LE, are used as arguments when initiating a process. Because any standard user with system access can modify these files, an attacker can overwrite or edit them to specify a path to an arbitrary executable. This executable will then be launched by the id service.exe process with SYSTEM privileges, potentially allowing for privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05823
CVE-2026-1995

Produtos afetados

I-Drive