PT-2020-6832 · G Data · G-Data
Published
2020-08-23
·
Updated
2021-07-21
·
CVE-2020-27172
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
G-Data versions prior to 25.5.9.25
Description
The issue is related to the infected-file restore mechanism in G-Data, which can be abused using symbolic links to achieve arbitrary write, leading to elevation of privileges. This can be exploited by an attacker to gain higher privileges. The vulnerability is associated with incorrect link resolution before file access.
Recommendations
For versions prior to 25.5.9.25, update to version 25.5.9.25 or later to resolve the issue. As a temporary workaround, consider restricting access to the infected-file restore mechanism until a patch is applied.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
G-Data