<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>StableBit - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/stablebit/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 07 Aug 2026 05:30:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/stablebit/feed.xml" rel="self" type="application/rss+xml"/><item><title>Local Privilege Escalation in StableBit DrivePool</title><link>https://feed.craftedsignal.io/briefs/2026-08-stablebit-drivepool-lpe/</link><pubDate>Fri, 07 Aug 2026 05:30:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-stablebit-drivepool-lpe/</guid><description>StableBit DrivePool version 2.3.13.1687 contains a local privilege escalation vulnerability in the DrivePoolService component stemming from improper permission management and insecure deserialization.</description><content:encoded><![CDATA[<p>StableBit DrivePool version 2.3.13.1687 is susceptible to a high-severity local privilege escalation vulnerability, tracked as CVE-2026-19191. The vulnerability is located within the DrivePoolService component, specifically within the DrivePool.Service.exe executable. According to vulnerability disclosures, the flaw is rooted in incorrect privilege assignment and permission issues, potentially exacerbated by insecure deserialization.</p>
<p>An attacker who has already achieved local access to a system running the affected version can exploit this vulnerability to manipulate the service and gain elevated privileges. The exploit has been disclosed publicly, increasing the risk of abuse by threat actors looking to gain administrative control after initial foothold establishment. Organizations utilizing this software on Windows environments should verify versioning and prioritize patching or isolating the service until a secure version is deployed.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local user to escalate privileges to the level of the DrivePoolService, which typically operates with elevated system-level permissions. This can result in complete system compromise, unauthorized data access, and persistent control over the host. The vulnerability is rated with a CVSS 3.1 base score of 7.8, reflecting the significant risk of full administrative access once local access is achieved.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all systems in the environment running StableBit DrivePool version 2.3.13.1687.</li>
<li>Update StableBit DrivePool to the latest patched version to remediate CVE-2026-19191.</li>
<li>Monitor file integrity for C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe to detect unauthorized modifications or suspicious process behavior associated with the service.</li>
<li>Implement strict access control lists (ACLs) on the DrivePool service directory to prevent unauthorized local users from modifying or interacting with the service executable.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>