logo

The Backup Backdoor: How a Simple File Edit Grants Full SYSTEM Control in IDrive for Windows

ID: f4a52a43-0076-5128-91e3-09ae0053c635

STIX ID: report--f4a52a43-0076-5128-91e3-09ae0053c635

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-26

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical local privilege escalation (CVE-2026-1995) in IDrive Cloud Backup for Windows (<= 7.0.0.63) allows authenticated, low-privilege users to modify UTF-16LE configuration files under C:\ProgramData\IDrive that id_service.exe (running as SYSTEM) uses to launch processes, enabling arbitrary code execution with SYSTEM-level privileges; IDrive plans a patch and interim mitigations include removing standard-user write permissions, using EDR, and applying Group Policy hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.