PT-2020-6832 · G Data · G-Data

Published

2020-08-23

·

Updated

2021-07-21

·

CVE-2020-27172

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions G-Data versions prior to 25.5.9.25
Description The issue is related to the infected-file restore mechanism in G-Data, which can be abused using symbolic links to achieve arbitrary write, leading to elevation of privileges. This can be exploited by an attacker to gain higher privileges. The vulnerability is associated with incorrect link resolution before file access.
Recommendations For versions prior to 25.5.9.25, update to version 25.5.9.25 or later to resolve the issue. As a temporary workaround, consider restricting access to the infected-file restore mechanism until a patch is applied.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00261
CVE-2020-27172

Affected Products

G-Data