CVE-2025-67794
Unknown
Unknown - Not Provided
Overly Permissive ACLs in DriveLock Agent Allow Local Exploitation
Publication date: 2025-12-17
Last updated on: 2025-12-18
Assigner: MITRE
Description
Description
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are created with overly permissive ACLs, allowing local users without administrator rights to trigger actions or destabilize the agent.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| drivelock | drivelock | From 24.1 (inc) to 24.1.4 (inc) |
| drivelock | drivelock | From 24.2 (inc) to 24.2.8 (exc) |
| drivelock | drivelock | From 25.1 (inc) to 25.1.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |