Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing a crafted ZIP archive in a globally writable directory, which gets unpacked in the context of SYSTEM and results in arbitrary file write.
Metrics
Affected Vendors & Products
References
History
Sat, 25 Jan 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing a crafted ZIP archive in a globally writable directory, which gets unpacked in the context of SYSTEM and results in arbitrary file write. | |
Title | G DATA Management Server Local privilege escalation | |
Weaknesses | CWE-22 CWE-276 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cirosec
Published:
Updated: 2025-02-12T20:01:14.392Z
Reserved: 2025-01-17T07:53:19.796Z
Link: CVE-2025-0542

No data.

Status : Received
Published: 2025-01-25T17:15:21.030
Modified: 2025-01-25T17:15:21.030
Link: CVE-2025-0542

No data.