Drivelock develops an endpoint and data-protection platform concentrated in a single product line that sits in a privileged position across managed environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and cluster around access-control and authentication weaknesses—including improper privilege management, broken access controls, insufficient authentication mechanisms, and cross-site scripting—that are characteristic of security-focused software handling sensitive user and system operations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Drivelock over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67793CRITICAL An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselve | Dec 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-55187CRITICAL In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges. | Sep 26, 2025 | 9.9 | 32 | NO | NO |
CVE-2025-67791CRITICAL An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allow | Dec 17, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-67781CRITICAL An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privi | Dec 17, 2025 | 9.9 | 29 | NO | NO |
CVE-2025-67790HIGH An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on | Dec 17, 2025 | 7.5 | 28 | NO | NO |
CVE-2025-67787CRITICAL An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network. | Dec 17, 2025 | 9.6 | 28 | NO | NO |
CVE-2025-67792HIGH An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate a DriveLock process to execute arbitrar | Dec 17, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-67794MEDIUM An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are created with overly permissive | Dec 17, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-67789MEDIUM An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants | Dec 17, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Drivelock.
Media articles that mention a CVE ID that affects a product developed by Drivelock — matched by CVE ID, not by vendor name.