PT-2025-3947 · G Data · G Data Management Server

Fabian Duschek

·

Publicado

2025-01-17

·

Atualizado

2025-01-25

·

CVE-2025-0542

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: G DATA Management Server versions are not explicitly specified in the provided sources.
Description: The issue is related to incorrect assignment of privileges of temporary files in the update mechanism, allowing a local, unprivileged attacker to escalate privileges by placing a crafted ZIP archive in a globally writable directory. This results in arbitrary file write in the context of SYSTEM.
Recommendations: No specific versions of G DATA Management Server are mentioned, thus no explicit recommendations can be provided based on the given data.

Exploit

Correção

LPE

Path traversal

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-16241
CVE-2025-0542

Produtos afetados

G Data Management Server