Back

HIGH

IDrive Cloud Backup Client for Windows contains a privilege escalation vulnerability

Published Mar 24, 2026

Description

In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any standard user logged into the system. An attacker can overwrite or edit the files to specify a path to an arbitrary executable, which will then be executed by the id_service.exe process with SYSTEM privileges.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Mar 24, 2026
Updated Jul 21, 2026
Reserved Feb 5, 2026
CISA Vulnrichment
Updated Mar 25, 2026
NVD
Status Awaiting Analysis
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a