CVE 9.8 CRITICAL

CVE-2025-67793_CVE-2025-67793

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This privilege is included by default in the Administrator role. This issue mainly affects cloud multi-tenant deployments; on-prem single-tenant installations are typically not impacted because local admins usually already have Supervisor privileges.

AI Analysis

Privilege escalation vulnerability in DriveLock allowing users with 'Manage roles and permissions' privilege to promote themselves or others to the Supervisor role

Basic Information

ID CVE-2025-67793
Source mitre
Published Dec 17, 2025 at 00:00
Modified Dec 18, 2025 at 19:53

Affected Product

Vendor CenterTools
Product DriveLock
Version 24.1, 24.2, 25.1
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor CenterTools
Product DriveLock
Version 24.1, 24.2, 25.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.