search menu icon-carat-right cmu-wordmark

CERT Coordination Center

IDrive for Windows contains local privilege escalation vulnerability

Vulnerability Note VU#330121

Original Release Date: 2026-03-24 | Last Revised: 2026-07-17

Overview

The IDrive Cloud Backup Client for Windows, versions 7.0.0.63 and earlier, contains a privilege escalation vulnerability that allows any authenticated user to run arbitrary executables with NT AUTHORITY\SYSTEM permissions.

Description

IDrive is a cloud backup service that allows users to encrypt, sync, and store data from multiple devices such as PCs, Macs, iPhones, and Androids in one cloud-based account. IDrive provides a Windows client for both desktop and server editions, which acts as both a thick client and a thin client with a web interface to manage cloud backups.

CVE-2026-1995 The IDrive Windows client utility id_service.exe runs as a process with elevated SYSTEM privileges and regularly reads from several files located under C:\ProgramData\IDrive. The UTF16-LE encoded contents of these files are used by the service as arguments for starting processes. Because of weak permission configurations, these files can be edited by any standard user logged into the system. An authenticated, low-privilege attacker can overwrite or add a new file that specifies a path to an arbitrary script or .exe, which will then be executed by the id_service.exe process with SYSTEM privileges.

Impact

This vulnerability enables an authenticated local user, or any user with access to the affected directory, to execute arbitrary code as SYSTEM on the target Windows device. A local attacker could exploit this vulnerability to escalate privileges and gain full control over the target machine, potentially enabling data theft, system modification, or arbitrary script execution.

Solution

IDrive has remediated this vulnerability in the recent 7.0.0.64 release. Users and organizations are advised to update their software to the latest version whenever possible.

Acknowledgements

Thanks to Matthew Owens and FRSecure for discovering and reporting this vulnerability. This document was written by Molly Jaconski.

Vendor Information

330121
 

IDrive Affected

Notified:  2025-12-03 Updated: 2026-07-17

Statement Date:   July 14, 2026

CVE-2026-1995 Affected

Vendor Statement

IDrive has released version 7.0.0.64 of the IDrive Windows Backup Client, which addresses CVE-2026-1995. Customers using affected versions are advised to update to version 7.0.0.64 or later to remediate this vulnerability. We appreciate the responsible disclosure and coordination throughout this process.


Other Information

CVE IDs: CVE-2026-1995
API URL: VINCE JSON | CSAF
Date Public: 2026-03-24
Date First Published: 2026-03-24
Date Last Updated: 2026-07-17 17:21 UTC
Document Revision: 3

Sponsored by CISA.