PT-2025-3948 · G Data · G Data Security Client
Fabian Duschek
·
Published
2025-01-24
·
Updated
2025-01-25
·
CVE-2025-0543
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
G DATA Security Client versions are not explicitly specified in the provided descriptions.
Description:
The issue is related to incorrect assignment of privileges to directories in G DATA Security Client, allowing a local, unprivileged attacker to escalate privileges on affected installations. This is achieved by placing an arbitrary executable in a globally writable directory, which results in execution by the SetupSVC.exe service in the context of SYSTEM. No information is provided about the estimated number of potentially affected devices or real-world incidents.
Recommendations:
No specific versions of G DATA Security Client are mentioned, thus no explicit recommendations can be provided based on the given input data.
Exploit
Fix
LPE
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
G Data Security Client