CVE-2026-13268: G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability
G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Backup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28665.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
G DATA Total Security Backup Serviceto a version that resolves this vulnerability.Patch ZDI-CAN-28665
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13268?
CVE-2026-13268 has a high severity rating of 7.8.
How do I fix CVE-2026-13268?
To fix CVE-2026-13268, ensure that you update G DATA Total Security to the latest version provided by the vendor.
What type of vulnerability is CVE-2026-13268?
CVE-2026-13268 is a local privilege escalation vulnerability.
Who is affected by CVE-2026-13268?
Users of G DATA Total Security can be affected by CVE-2026-13268 if an attacker gains low-privileged access.
What exploitation method is used in CVE-2026-13268?
CVE-2026-13268 requires an attacker to execute low-privileged code before escalating privileges.