SB2020082304 - Privilege escalation in G DATA Internet Security



SB2020082304 - Privilege escalation in G DATA Internet Security

Published: August 23, 2020 Updated: December 4, 2020

Security Bulletin ID SB2020082304
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Link following (CVE-ID: N/A)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the application follows symbolic links when restoring files. A local user can create a specially crafted file that points to a critical file on the system and abuse the file restore mechanism to overwrite arbitrary files on the system.

Successful exploitation of the vulnerability may allow privilege escalation.


Remediation

Install update from vendor's website.