The Backup Backdoor: How a Simple File Edit Grants Full SYSTEM Control in IDrive for Windows
ID: f4a52a43-0076-5128-91e3-09ae0053c635
STIX ID: report--f4a52a43-0076-5128-91e3-09ae0053c635
Feed Name: securityonline.info
A critical local privilege escalation (CVE-2026-1995) in IDrive Cloud Backup for Windows (<= 7.0.0.63) allows authenticated, low-privilege users to modify UTF-16LE configuration files under C:\ProgramData\IDrive that id_service.exe (running as SYSTEM) uses to launch processes, enabling arbitrary code execution with SYSTEM-level privileges; IDrive plans a patch and interim mitigations include removing standard-user write permissions, using EDR, and applying Group Policy hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
