Executive brief
IDrive is a cloud backup service used to protect and sync data across multiple devices. A security flaw in its Windows software allows a standard user on a computer to gain full administrative control (SYSTEM privileges). By modifying specific configuration files, an attacker can force the backup service to run malicious programs, potentially leading to data theft or complete system takeover.
Technical details
A local privilege escalation vulnerability exists in IDrive Cloud Backup Client for Windows versions prior to 7.0.0.64. The 'id_service.exe' process runs with SYSTEM privileges and periodically reads UTF16-LE encoded files from 'C:\ProgramData\IDrive\' to use as process execution arguments. Due to weak ACLs on this directory, any authenticated low-privileged user can modify these files or create new ones. By injecting a path to a malicious executable or script into these files, an attacker can achieve arbitrary code execution as NT AUTHORITY\SYSTEM. The issue is resolved in version 7.0.0.64.
Affected products
- IDrive IDrive Cloud Backup Client for Windows Before 7.0.0.64
Timeline
- 2025-12-03: other: Vendor notified
- 2026-03-24: disclosed
- 2026-03-24: advisory
- 2026-07-14: patched: Vendor statement confirming fix in 7.0.0.64