CVE-2020-15351: Idrive

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

IDrive before 6.7.3.19 on Windows installs by default to %PROGRAMFILES(X86)%\IDriveWindows with weak folder permissions granting any user modify permission (i.e., NT AUTHORITY\Authenticated Users:(OI)(CI)(M)) to the contents of the directory and its sub-folders. In addition, the program installs a service called IDriveService that runs as LocalSystem. Thus, any standard user can escalate privileges to NT AUTHORITY\SYSTEM by substituting the service's binary with a malicious one.

Affected products

  • Idrive Idrive: before 6.7.3.19 (fixed in 6.7.3.19)

Published 2020-06-26. Last modified 2026-06-17.