{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/stablebit/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-19191"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DrivePool (2.3.13.1687)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["StableBit"],"content_html":"\u003cp\u003eStableBit DrivePool version 2.3.13.1687 is susceptible to a high-severity local privilege escalation vulnerability, tracked as CVE-2026-19191. The vulnerability is located within the DrivePoolService component, specifically within the DrivePool.Service.exe executable. According to vulnerability disclosures, the flaw is rooted in incorrect privilege assignment and permission issues, potentially exacerbated by insecure deserialization.\u003c/p\u003e\n\u003cp\u003eAn attacker who has already achieved local access to a system running the affected version can exploit this vulnerability to manipulate the service and gain elevated privileges. The exploit has been disclosed publicly, increasing the risk of abuse by threat actors looking to gain administrative control after initial foothold establishment. Organizations utilizing this software on Windows environments should verify versioning and prioritize patching or isolating the service until a secure version is deployed.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local user to escalate privileges to the level of the DrivePoolService, which typically operates with elevated system-level permissions. This can result in complete system compromise, unauthorized data access, and persistent control over the host. The vulnerability is rated with a CVSS 3.1 base score of 7.8, reflecting the significant risk of full administrative access once local access is achieved.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all systems in the environment running StableBit DrivePool version 2.3.13.1687.\u003c/li\u003e\n\u003cli\u003eUpdate StableBit DrivePool to the latest patched version to remediate CVE-2026-19191.\u003c/li\u003e\n\u003cli\u003eMonitor file integrity for C:\\Program Files\\StableBit\\DrivePool\\DrivePool.Service.exe to detect unauthorized modifications or suspicious process behavior associated with the service.\u003c/li\u003e\n\u003cli\u003eImplement strict access control lists (ACLs) on the DrivePool service directory to prevent unauthorized local users from modifying or interacting with the service executable.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T05:30:55Z","date_published":"2026-08-07T05:30:55Z","id":"https://feed.craftedsignal.io/briefs/2026-08-stablebit-drivepool-lpe/","summary":"StableBit DrivePool version 2.3.13.1687 contains a local privilege escalation vulnerability in the DrivePoolService component stemming from improper permission management and insecure deserialization.","title":"Local Privilege Escalation in StableBit DrivePool","url":"https://feed.craftedsignal.io/briefs/2026-08-stablebit-drivepool-lpe/"}],"language":"en","title":"CraftedSignal Threat Feed - StableBit","version":"https://jsonfeed.org/version/1.1"}