Executive brief
DriveLock Enterprise Service, a platform used for endpoint security and device control, contains a vulnerability in its web service. An unauthenticated attacker can exploit this flaw to access sensitive configuration data that should be restricted to internal users. This could lead to the exposure of global or tenant-specific settings, potentially aiding further attacks against the organization's security infrastructure.
Technical details
A directory traversal vulnerability exists in the DriveLock Enterprise Service (DES) web API, which typically listens on TCP port 4568. The flaw is caused by a misconfigured reverse proxy and a lack of proper validation of user-supplied paths before they are used in file operations. By using URL manipulation and encoding techniques (such as obfuscating '..' sequences), a remote, unauthenticated attacker can bypass access controls to reach internal endpoints. This allows for the unauthorized retrieval of global and tenant configuration files in the context of the service account. The issue is addressed in versions 24.2.9, 25.1.7, and 25.2.4.
Affected products
- DriveLock DriveLock Enterprise Service (DES) <= 24.2.8, <= 25.1.6, <= 25.2.3
Timeline
- 2026-02-06: disclosed: Vulnerability reported to vendor
- 2026-02-06: patched: First published date of security bulletin
- 2026-04-15: advisory: Coordinated public release by ZDI
- 2026-07-29: advisory: NVD publication date