CVE Database
/

CVE-2026-1995

Back to search

CVE-2026-1995

Published: Mar 24, 2026

Modified: Mar 25, 2026

PUBLISHED

Description

IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any standard user logged into the system. An attacker can overwrite or edit the files to specify a path to an arbitrary executable, which will then be executed by the id_service.exe process with SYSTEM privileges.

VendorProductVersions

IDrive

IDrive Cloud Backup Client for Windows

affected
0 - < 7.0.0.63

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now