PT-2025-3947 · G Data · G Data Management Server

Fabian Duschek

·

Published

2025-01-17

·

Updated

2025-01-25

·

CVE-2025-0542

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: G DATA Management Server versions are not explicitly specified in the provided sources.
Description: The issue is related to incorrect assignment of privileges of temporary files in the update mechanism, allowing a local, unprivileged attacker to escalate privileges by placing a crafted ZIP archive in a globally writable directory. This results in arbitrary file write in the context of SYSTEM.
Recommendations: No specific versions of G DATA Management Server are mentioned, thus no explicit recommendations can be provided based on the given data.

Exploit

Fix

LPE

Path traversal

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2025-16241
CVE-2025-0542

Affected Products

G Data Management Server