SB2020082304 - Privilege escalation in G DATA Internet Security
Published: August 23, 2020 Updated: December 4, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Link following (CVE-ID: N/A)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application follows symbolic links when restoring files. A local user can create a specially crafted file that points to a critical file on the system and abuse the file restore mechanism to overwrite arbitrary files on the system.
Successful exploitation of the vulnerability may allow privilege escalation.
Remediation
Install update from vendor's website.