Microsoft OneDrive for Android Path Traversal Vulnerability Allowing Privilege Escalation

Vulnerability

A path traversal vulnerability has been identified in OneDrive for Android, allowing an authorized attacker to elevate privileges over a network. This issue arises from improper restriction of pathname access to certain directories.

Impact

Exploitation of this vulnerability could enable an attacker to gain unauthorized access to system resources, allowing actions to be performed with the same privileges as the compromised process. This could result in further system compromise and unauthorized activities within the network.

Remediation

Users can download the security update for OneDrive for Android from the Google Play Store.

Added: Nov 11, 2025, 7:15 PM
Updated: Nov 11, 2025, 7:15 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
3.3
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.