Gbhackers Critical IDrive Vulnerability Allows Privilege Escalation on Windows
Article Content
- •CVE-2026-1995 allows local privilege escalation for authenticated users on IDrive Windows client.
- •Weak permissions on C:\ProgramData\IDrive enable arbitrary code execution with SYSTEM privileges.
- •No patch is currently available; users should restrict directory permissions and monitor for changes.
A critical vulnerability, tracked as CVE-2026-1995, has been discovered in the IDrive Cloud Backup Client for Windows, affecting versions 7.0.0.63 and earlier. This flaw allows authenticated low-privilege users to execute arbitrary code with SYSTEM-level permissions, potentially compromising the entire device. The vulnerability arises from weak permission settings on files within the C:\ProgramData\IDrive directory, enabling attackers to overwrite or add files that the id_service.exe process executes with elevated privileges. Currently, there is no patch available, but IDrive has confirmed that a security update is in development. Organizations are advised to restrict write permissions on the affected directory and implement monitoring solutions to detect unauthorized changes. The vulnerability poses significant risks, including data theft and system modification. Security teams should remain vigilant until a patch is released.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Kiss Loader and CVE-2026-1995 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…