CVE-2026-1995Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any standard user logged into the system. An attacker can overwrite or edit the files to specify a path to an arbitrary executable, which will then be executed by the id_service.exe process with SYSTEM privileges.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-26); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-26: 4Mentions · 2026-03-27: 1Mentions · 2026-04-02: 1Patch / Workaround · 2026-03-26: 2Technical Details · 2026-03-26: 4Technical Details · 2026-03-27: 1Technical Details · 2026-04-02: 103-2603-2704-02
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-264
Disclosure3Patch1
2026-03-271
Disclosure1
2026-04-021
Disclosure1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    A critical flaw in IDrive for Windows (CVE-2026-1995) allows low-privilege users to seize SYSTEM control via weak folder permissions. Audit your PC today. #IDrive #CyberSecurity #InfoSec #WindowsSecurity #PrivilegeEscalation #LPE #Vulnerability https://securityonline.info/idrive-windows-client-privilege-escalation-vulnerability-cve-2026-1995/ https://t.co/mxx0sRCreH

    Post summary

    The tweet announces CVE‑2026‑1995, a critical privilege‑escalation flaw in IDrive for Windows, and directs readers to a security article for further details.

    070213937
    10.9K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    IDrive for Windows (≤7.0.0.63) allows any authenticated user to escalate to SYSTEM via writable files in C:\ProgramData\IDrive that control service execution (CVE-2026-1995). Restrict directory permissions until patch arrives. #DFIR_Radar https://t.co/HZTlFh2fQr

    Post summary

    The text warns of a privilege‑escalation flaw in IDrive for Windows, recommending directory permission restriction and awaiting vendor patch.

    10010172
    1.0K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    IDrive の未パッチ脆弱性 CVE-2026-1995:SYSTEM 権限での任意のコード実行の恐れ https://iototsecnews.jp/2026/03/26/idrive-for-windows-vulnerability-allows-attackers-to-escalate-privileges-and-gain-unauthorized-access/ 脆弱性 CVE-2026-1995 により、高い権限で動作するサービスと、誰でも書き込みができるフォルダ設定の組み合わせが可能になっています。Windows で動作する “id_service.exe” というプログラムは、特定のフォルダ内にあるファイルを読み取り、新しいプロセスを開始する仕組みになっていますが、そのフォルダのアクセス権限 (パーミッション) 設定が適切ではありませんでした。その結果として、本来は操作できないはずの一般ユーザーが、当該フォルダの中身を書き換え、悪意のプログラムを実行させることが可能になっています。ご利用のチームは、ご注意ください。 #CloudBackupClient #CVE20261995 #IDrive #Vulnerability

    Post summary

    An unpatched IDrive Windows service flaw (CVE‑2026‑1995) permits low‑privileged users to write to a misconfigured folder and trigger SYSTEM‑level code execution.

    01000186
    481 followersView on X
  • Jamaica Cyber Incident Response Team (JaCIRT)@cirtgovjm
    Disclosure

    A critical vulnerability, tracked as CVE-2026-1995, has been identified in the IDrive Cloud Backup Client for Windows. The flaw affects version 7.0.0.63 and earlier. Click here for more details👇 https://cirt.gov.jm/advisory/idrive-windows-vulnerability-let-attackers-escalate-privileges #jacirt #cirt #cirtdiv #idrive #securityadvisory https://t.co/Utc1328MOF

    Post summary

    The advisory announces a critical privilege‑escalation CVE affecting IDrive Cloud Backup Client versions 7.0.0.63 and earlier, but does not provide a PoC, exploit code, or evidence of active exploitation.

    0000076
    1.1K followersView on X
  • Israel@f1tym1
    Disclosure

    IDrive for Windows Vulnerability Let Attackers Escalate Privileges https://ift.tt/Jh8ir3c A critical local privilege escalation vulnerability has been identified in the IDrive Cloud Backup Client for Windows. Tracked as CVE-2026-1995, this local privilege escalation vulnerab…

    Post summary

    The tweet announces CVE‑2026‑1995, a critical local privilege escalation flaw in IDrive Cloud Backup Client for Windows, without PoC, exploit, patch, or active exploitation details.

    0000038
    954 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: CVE-2026-1995 in IDrive for Windows v7.0.0.63 and earlier lets any authenticated user gain NT AUTHORITY\SYSTEM via weak C:\ProgramData\IDrive permissions, patch pending. https://threatcluster.io/cluster/critical-local-privilege-escalation-vulnerability-in-idrive--22bdd2a3

    Post summary

    A new local privilege escalation CVE‑2026‑1995 in IDrive for Windows allows authenticated users to acquire SYSTEM privileges due to weak permissions, with a patch pending.

    0000044
    115 followersView on X

Explore more