Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25295.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.zerodayinitiative.com/advisories/ZDI-25-183/ |
![]() ![]() |
History
Wed, 23 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 23 Apr 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25295. | |
Title | Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: zdi
Published: 2025-04-23T16:51:39.300Z
Updated: 2025-04-23T17:59:45.711Z
Reserved: 2025-03-24T19:43:45.762Z
Link: CVE-2025-2769

Updated: 2025-04-23T17:59:41.103Z

Status : Awaiting Analysis
Published: 2025-04-23T17:16:54.903
Modified: 2025-04-29T13:52:47.470
Link: CVE-2025-2769

No data.