Executive brief
DriveLock Enterprise Service, a platform used for endpoint security and device control, contains a security flaw in its web service. An unauthenticated remote attacker can exploit this to access sensitive files stored on the server's file system. This could lead to the exposure of configuration data or other internal information, potentially compromising the security of the managed environment.
Technical details
A directory traversal vulnerability (CWE-22) exists in the DriveLock Enterprise Service (DES) web service, which typically listens on TCP port 4568. The flaw is caused by insufficient validation of user-supplied file paths containing sequences such as '..'. An unauthenticated remote attacker can exploit this by sending a crafted network request to access arbitrary files outside the intended directory in the context of the service account. The vulnerability is fixed in versions 24.2.9, 25.1.7, and 25.2.4.
Affected products
- DriveLock DriveLock Enterprise Service (DES) <= 24.2.8, <= 25.1.6, <= 25.2.3
Timeline
- 2026-02-06: disclosed: Vulnerability reported to vendor
- 2026-02-06: patched: First publication of security bulletin by vendor
- 2026-04-15: advisory: Coordinated public release of ZDI advisory
- 2026-07-29: other: NVD publication date