First published: Sat Jan 25 2025(Updated: )
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in execution by the SetupSVC.exe service in the context of SYSTEM.
Credit: a341c0d1-ebf7-493f-a84e-38cf86618674
Affected Software | Affected Version | How to fix |
---|---|---|
G DATA Security Client |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0543 is classified as a high severity vulnerability due to its potential for local privilege escalation.
The fix for CVE-2025-0543 involves applying the latest updates and patches provided by G DATA for the G DATA Security Client.
CVE-2025-0543 affects users of the G DATA Security Client who have an installation vulnerable to incorrect directory privilege assignments.
CVE-2025-0543 allows local unprivileged attackers to escalate their privileges by placing an executable in a writable directory.
CVE-2025-0543 was reported in 2025, highlighting a security issue in the G DATA Security Client.