logo

IDrive for Windows Vulnerability Let Attackers Escalate Privileges

ID: ad17620f-a331-5a99-b6d2-f1869a21630b

STIX ID: report--ad17620f-a331-5a99-b6d2-f1869a21630b

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-26

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical local privilege escalation (CVE-2026-1995) in the IDrive Cloud Backup Client for Windows (versions 7.0.0.63 and earlier) stems from weak permissions on the C:\ProgramData\IDrive directory and use of UTF-16 LE-encoded config files as process arguments, allowing an authenticated low-privilege user to modify config files and obtain SYSTEM-level code execution; vendor patch is pending and interim mitigations include tightening directory write permissions and monitoring for unauthorized file modifications and suspicious child processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.