CVE-2025-67781

CRITICAL

Drivelock < 24.1.6 - Improper Privilege Management

Title source: rule
STIX 2.1

Description

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privileges on Windows computers.

Scores

CVSS v3 9.9
EPSS 0.0008
EPSS Percentile 22.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
drivelock/drivelock 24.1 - 24.1.6
Published Dec 17, 2025
Tracked Since Feb 18, 2026