Executive brief
DriveLock Enterprise Service, a platform used for endpoint security and device control, contains a vulnerability in its web service. An authenticated attacker can exploit this flaw to access sensitive files on the server that should normally be restricted. This could lead to the exposure of configuration data or other internal system information, potentially compromising the security of the management infrastructure.
Technical details
A directory traversal vulnerability exists within the DriveLock Enterprise Service (DES) web service, which typically listens on TCP port 4568. The root cause is a failure to properly validate user-supplied file paths before they are used in file system operations. An authenticated remote attacker can use directory traversal sequences (e.g., '..') to bypass intended directory restrictions and read arbitrary files in the security context of the service account. The vulnerability is addressed in versions 24.2.9, 25.1.7, and 25.2.4.
Affected products
- DriveLock DriveLock Enterprise Service (DES) <= 24.2.8, <= 25.1.6, <= 25.2.3
Timeline
- 2026-02-06: disclosed: Vulnerability reported to vendor
- 2026-02-06: advisory: First published by vendor
- 2026-04-15: advisory: Coordinated public release by ZDI
- 2026-07-29: patched: NVD publication date