PT-2025-3947 · G Data · G Data Management Server
Fabian Duschek
·
Published
2025-01-17
·
Updated
2025-01-25
·
CVE-2025-0542
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
G DATA Management Server versions are not explicitly specified in the provided sources.
Description:
The issue is related to incorrect assignment of privileges of temporary files in the update mechanism, allowing a local, unprivileged attacker to escalate privileges by placing a crafted ZIP archive in a globally writable directory. This results in arbitrary file write in the context of SYSTEM.
Recommendations:
No specific versions of G DATA Management Server are mentioned, thus no explicit recommendations can be provided based on the given data.
Exploit
Fix
LPE
Path traversal
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
G Data Management Server