First published: Wed Mar 13 2019(Updated: )
gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\gdwfpcd device are not properly protected, leading to unintended impersonation or object creation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gdata-software Total Security | <2019-02-22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.