Sceawere

Vulnerability Detail

CVE-2026-19191UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DrivePool Service Local Permission Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
StableBit
Product
DrivePool
Attack Type
Permission Issues
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-07T05:17:01.313Z",
  "pubdate": "2026-08-07T05:17:01.313Z",
  "executiveSummary": "A permission-related security vulnerability has been identified within StableBit DrivePool version 2.3.13.1687, specifically impacting the DrivePoolService component. The flaw resides within the executable file located at C:\\Program Files\\StableBit\\DrivePool\\DrivePool.Service.exe and stems from improper handling of access controls or operational permissions. Successful exploitation of this vulnerability can result in local privilege manipulation or unauthorized access conditions within the host operating system. The vulnerability is classified as a local attack vector, meaning that an unprivileged or malicious actor must already have local access to the target machine to initiate the exploit sequence. Public disclosure of functional exploit code increases the urgency for defenders to address the risk, as threat actors can leverage existing exploit material to compromise system integrity or escalate local privileges. Because the attack surface is constrained to the local host environment, remote execution is not feasible without a pre-existing remote access vector. Organizations utilizing the affected software version face increased exposure to internal security degradation, emphasizing the necessity for prompt administrative oversight and defensive hardening measures.",
  "technicalDetails": "The vulnerability resides in the DrivePoolService component of StableBit DrivePool 2.3.13.1687, specifically targeting the binary file C:\\Program Files\\StableBit\\DrivePool\\DrivePool.Service.exe. The root cause pertains to insecure permission configurations, which may manifest as improperly assigned Access Control Lists (ACLs), insecure object creation, or flawed authorization checks within the service execution context. Because DrivePool.Service.exe typically executes with elevated system privileges to manage storage pools and file system operations, any weakness in its permission model exposes critical system surfaces to local manipulation.\nThe exploitation method requires local execution capabilities, meaning the adversary must possess interactive logon access or a pre-established execution vector on the target system. Due to the public disclosure of the exploit, attackers can programmatically or manually interact with the vulnerable service binary or its associated inter-process communication mechanisms. The attack flow initiates with the local user identifying the permission flaw within the C:\\Program Files\\StableBit\\DrivePool\\DrivePool.Service.exe file path or its running service context. By exploiting the permissive access controls, the local attacker can manipulate the service behavior, inject arbitrary payloads, or alter critical operational parameters that the service processes with elevated privileges.\nAuthentication and privilege requirements are constrained to local execution; however, the impact often allows a standard local user to achieve unauthorized actions or privilege escalation depending on the exact nature of the permission flaw. The network exposure for this vulnerability is strictly local, precluding direct remote exploitation over network protocols. The post-exploitation impact includes unauthorized modification of system resources, potential elevation of privilege to the security context of the DrivePool.Service.exe process, and compromise of local host integrity. Remediation requires strict auditing of file and service permissions to ensure that only authorized administrative entities can modify or interact with the affected binary and its operational state."
}
CVE-2026-19191: DrivePool Service Local Permission Vulnerability (HIGH Severity, CVSS: 7.8) - Sceawere