Privacy Drive Unquoted Service Path Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in Privacy Drive version 3.17.0. The issue arises from an unquoted service path in the 'pdsvc.exe' service binary, which allows local attackers to exploit the service startup process. By placing malicious executables in the unquoted path directories, attackers can execute arbitrary code with LocalSystem privileges during service startup or system reboot.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing local attackers to execute code with elevated rights.

Reproduction

The vulnerability can be reproduced by placing a malicious executable in the directory path specified by the unquoted service path of 'pdsvc.exe'. This can be done manually or through a script. Once the executable is in place, the service can be restarted or the system can be rebooted, at which point the malicious code will be executed with LocalSystem privileges.

Added: May 16, 2026, 4:37 PM
Updated: May 16, 2026, 4:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
8.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.