CVE-2020-27172

CRITICAL

G-Data <25.5.9.25 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file restore mechanism to achieve arbitrary write that leads to elevation of privileges.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.fortiguard.com/zeroday/FG-VD-20-120

Scores

CVSS v3 9.8
EPSS 0.0133
EPSS Percentile 67.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-59
Status published
Products (1)
gdatasoftware/g_data < 25.5.9.25
Published Dec 28, 2020
Tracked Since Feb 18, 2026