Drivelock

Drivelock

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 17.12.2025 20:15:57
  • Zuletzt bearbeitet 02.01.2026 15:55:01

An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.

  • EPSS 0.06%
  • Veröffentlicht 17.12.2025 20:15:56
  • Zuletzt bearbeitet 02.01.2026 15:55:28

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privileges on Windows computers.

  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 19:42:04

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API.

  • EPSS 0.07%
  • Veröffentlicht 17.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 20:16:08

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on Windows computers by using an IOCTL and an unterminated string.

  • EPSS 0.02%
  • Veröffentlicht 17.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 20:16:08

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate a DriveLock process to execute arbitrary commands on Windows computers.

  • EPSS 0.07%
  • Veröffentlicht 17.12.2025 00:00:00
  • Zuletzt bearbeitet 02.01.2026 15:54:36

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This ...

  • EPSS 0.1%
  • Veröffentlicht 17.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 20:16:08

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against ...

  • EPSS 0.02%
  • Veröffentlicht 17.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 20:16:08

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are created with overly permissive ACLs, allowing local users without administrator rights to trigger act...

  • EPSS 0.05%
  • Veröffentlicht 26.09.2025 15:16:03
  • Zuletzt bearbeitet 08.10.2025 20:20:03

In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges.