CVE-2020-15351: High severity idrive online backup vulnerability
IDrive before 6.7.3.19 on Windows installs by default to %PROGRAMFILES(X86)%\IDriveWindows with weak folder permissions granting any user modify permission (i.e., NT AUTHORITY\Authenticated Users:(OI)(CI)(M)) to the contents of the directory and its sub-folders. In addition, the program installs a service called IDriveService that runs as LocalSystem. Thus, any standard user can escalate privileges to NT AUTHORITY\SYSTEM by substituting the service's binary with a malicious one.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15351?
CVE-2020-15351 has a medium severity due to its weak folder permissions that allow unauthorized users to modify files.
How do I fix CVE-2020-15351?
To fix CVE-2020-15351, update to IDrive version 6.7.3.19 or later, which addresses the weak folder permissions issue.
Which versions of IDrive are affected by CVE-2020-15351?
IDrive versions prior to 6.7.3.19 are affected by CVE-2020-15351.
What systems are impacted by CVE-2020-15351?
CVE-2020-15351 impacts IDrive installations on Windows systems.
What are the risks of not addressing CVE-2020-15351?
Not addressing CVE-2020-15351 can lead to unauthorized access and potential data manipulation by any authenticated user.