CVE-2023-42126

NONE EPSS 31.4%
Published May 3, 20242y ago · Modified Jun 17, 20261w ago
Find Similar
Published May 3, 2024 2y ago
Last Modified Jun 17, 2026 1w ago

Description

G DATA Total Security GDBackupSvc Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G Data Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the GDBackupSvc service. By creating a symbolic link, an attacker can abuse the service to create a file with a permissive DACL. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-20694.

Threat Intelligence

EPSS Exploit Probability
31.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-59

Affected Products 1

VendorProductVersionRange
gdata-softwaretotal_security25.5.14.95any

References 1

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.