PT-2025-3947 · G Data · G Data Management Server
Fabian Duschek
·
Publicado
2025-01-17
·
Atualizado
2025-01-25
·
CVE-2025-0542
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
G DATA Management Server versions are not explicitly specified in the provided sources.
Description:
The issue is related to incorrect assignment of privileges of temporary files in the update mechanism, allowing a local, unprivileged attacker to escalate privileges by placing a crafted ZIP archive in a globally writable directory. This results in arbitrary file write in the context of SYSTEM.
Recommendations:
No specific versions of G DATA Management Server are mentioned, thus no explicit recommendations can be provided based on the given data.
Exploit
Correção
LPE
Path traversal
Incorrect Default Permissions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
G Data Management Server