DriveLock Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in DriveLock versions 24.1 prior to 24.1.6, 24.2 prior to 24.2.7, and 25.1 prior to 25.1.5. This vulnerability allows local unprivileged users to manipulate a DriveLock process, executing arbitrary commands on Windows systems.

Impact

Exploitation of this vulnerability allows local non-privileged users to gain elevated privileges, potentially leading to unauthorized access or control over system resources.

Remediation

Users are advised to update to DriveLock version 25.1.5. For those using DriveLock 24.1 or 24.2, the recommended update is to version 24.1.6 or 24.2.7, respectively. Older, unsupported versions are also affected but not eligible for patches.

Added: Dec 17, 2025, 9:18 PM
Updated: Dec 17, 2025, 9:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.3
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.