CVE-2020-27172

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
28/12/2020
Last modified:
21/07/2021

Description

An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file restore mechanism to achieve arbitrary write that leads to elevation of privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gdatasoftware:g_data:*:*:*:*:*:*:*:* 25.5.9.25 (excluding)


References to Advisories, Solutions, and Tools