CVE-2026-1995

HIGHCVSS 7.8/10EPSS 0.17%

Last modified

This CVE is reserved or awaiting analysis. Details will appear once published by NVD.

Description

IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any standard user logged into the system. An attacker can overwrite or edit the files to specify a path to an arbitrary executable, which will then be executed by the id_service.exe process with SYSTEM privileges.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.17%

6.7th percentile

Probability of exploitation in the next 30 days. Learn more

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Are you affected by CVE-2026-1995?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST