Impact
The vulnerability allows a local attacker to manipulate permissions in the DrivePoolService component of StableBit DrivePool 2.3.13.1687, potentially granting elevated privileges. This misconfiguration can let an attacker bypass intended access controls and gain higher system permissions on the host.
Affected Systems
Affected systems are installations of StableBit DrivePool version 2.3.13.1687 running on Windows, specifically the DrivePoolService component located in C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity local privilege escalation risk, while the EPSS score is not available, making the exact exploitation probability uncertain. The vulnerability is not in the CISA KEV catalog. Because the attack vector is local, only users with local system access can exploit it, and after successful execution, the attacker can elevate privileges, potentially compromising confidentiality, integrity, and availability.
OpenCVE Enrichment