Skip to content
Threat Feed
high advisory

Local Privilege Escalation in StableBit DrivePool

StableBit DrivePool version 2.3.13.1687 contains a local privilege escalation vulnerability in the DrivePoolService component stemming from improper permission management and insecure deserialization.

StableBit DrivePool version 2.3.13.1687 is susceptible to a high-severity local privilege escalation vulnerability, tracked as CVE-2026-19191. The vulnerability is located within the DrivePoolService component, specifically within the DrivePool.Service.exe executable. According to vulnerability disclosures, the flaw is rooted in incorrect privilege assignment and permission issues, potentially exacerbated by insecure deserialization.

An attacker who has already achieved local access to a system running the affected version can exploit this vulnerability to manipulate the service and gain elevated privileges. The exploit has been disclosed publicly, increasing the risk of abuse by threat actors looking to gain administrative control after initial foothold establishment. Organizations utilizing this software on Windows environments should verify versioning and prioritize patching or isolating the service until a secure version is deployed.

Impact

Successful exploitation allows a local user to escalate privileges to the level of the DrivePoolService, which typically operates with elevated system-level permissions. This can result in complete system compromise, unauthorized data access, and persistent control over the host. The vulnerability is rated with a CVSS 3.1 base score of 7.8, reflecting the significant risk of full administrative access once local access is achieved.

Recommendation

  • Identify all systems in the environment running StableBit DrivePool version 2.3.13.1687.
  • Update StableBit DrivePool to the latest patched version to remediate CVE-2026-19191.
  • Monitor file integrity for C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe to detect unauthorized modifications or suspicious process behavior associated with the service.
  • Implement strict access control lists (ACLs) on the DrivePool service directory to prevent unauthorized local users from modifying or interacting with the service executable.

Immediate actions

Patch all instances of StableBit DrivePool 2.3.13.1687 to the latest version.

IT Operations 48h

Threat Hunt

Identify local users with permission to interact with DrivePool.Service.exe or access its installation directory.

T1068 medium medium confidence hunt now

Data: File system ACL logs

Mitigations

Restrict local user access to the DrivePool installation folder and service configuration.

immediate IT Operations

CVE-2026-19191