← Vulnerability feed

Vulnerability record · CVE-2025-67793 · published 17 December 2025

CVE-2025-67793: Drivelock improper privilege management vulnerability

Drivelock · Drivelock

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This privilege is included by default in the Administrator role. This issue mainly affects cloud multi-tenant deployments; on-prem single-tenant installations are typically not impacted because local admins usually already have Supervisor privileges.

9.8 CVSS 3.1 Critical EPSS 0.32% · top 77.7% CWE-269 · Improper privilege management
9.8CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This privilege is included by default in the Administrator role. This issue mainly affects cloud multi-tenant deployments; on-prem single-tenant installations are typically not impacted because local admins usually already have Supervisor privileges.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-67793 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-67781Drivelock improper privilege management vulnerabilityAn issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileg…EPSS 0.28%9.9CVE-2025-55187Drivelock improper privilege management vulnerabilityIn DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges.EPSS 0.45%9.8CVE-2025-67791Drivelock improper authentication vulnerabilityAn issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentica…EPSS 0.37%9.6CVE-2025-67787Drivelock cross-site scripting vulnerabilityAn issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a…EPSS 0.26%7.8CVE-2025-67792Drivelock improper privilege management vulnerabilityAn issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate a DriveL…EPSS 0.14%7.5CVE-2025-67790Drivelock vulnerabilityAn issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a …EPSS 0.32%6.1CVE-2025-67794Drivelock incorrect permission assignment vulnerabilityAn issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are …EPSS 0.12%5.3CVE-2025-67789Drivelock improper access control vulnerabilityAn issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer co…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2025-67793), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.