PT-2025-3947 · G Data · G Data Management Server

·

CVE-2025-0542

·

Published

2025-01-17

·

Updated

2025-01-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: G DATA Management Server versions are not explicitly specified in the provided sources.
Description: The issue is related to incorrect assignment of privileges of temporary files in the update mechanism, allowing a local, unprivileged attacker to escalate privileges by placing a crafted ZIP archive in a globally writable directory. This results in arbitrary file write in the context of SYSTEM.
Recommendations: No specific versions of G DATA Management Server are mentioned, thus no explicit recommendations can be provided based on the given data.

Exploit

Fix

LPE

Path traversal

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16241
CVE-2025-0542

Affected Products

G Data Management Server