CVE-2025-67794 Details
Description
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are created with overly permissive ACLs, allowing local users without administrator rights to trigger actions or destabilize the agent.
A vulnerability exists in DriveLock Agent for Windows in versions 24.1 prior to 24.1.*, 24.2 prior to 24.2.8, and 25.1 prior to 25.1.6. The issue arises from directories and files created by the agent being assigned overly permissive Access Control Lists (ACLs). This misconfiguration allows local users without administrative privileges to initiate actions or disrupt the agent's functionality.
Users are advised to update to DriveLock versions 24.2.8 or 25.1.6. For optimal security and support, upgrading directly to DriveLock version 25.1 Patch 4 (25.1.6) is recommended. Note that older, unsupported versions are also affected but will not receive patches.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drivelock.help/sb/Content/SecurityBulletins/25-009-AgIncPermissions.htm | [email protected] | Release NotesVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-732 | Incorrect Permission Assignment for Critical Resource | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| drivelock drivelock | >= 24.1, <= 24.1.4 >= 24.2, < 24.2.8 >= 25.1, < 25.1.6 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Dec 17, 2025 | New CVE Received | [email protected] |