Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25041.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.zerodayinitiative.com/advisories/ZDI-25-182/ |
![]() ![]() |
History
Wed, 23 Apr 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 23 Apr 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25041. | |
Title | Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: zdi
Published: 2025-04-23T16:51:28.112Z
Updated: 2025-04-23T18:03:14.680Z
Reserved: 2025-03-24T19:43:36.448Z
Link: CVE-2025-2768

Updated: 2025-04-23T18:03:11.182Z

Status : Awaiting Analysis
Published: 2025-04-23T17:16:54.777
Modified: 2025-04-29T13:52:47.470
Link: CVE-2025-2768

No data.