ZDI-25-590: G DATA Total Security GDTunerSvc Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-2790.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-590?
The severity of ZDI-25-590 is classified as high due to its ability to allow privilege escalation.
How do I fix ZDI-25-590?
To fix ZDI-25-590, ensure that you update G DATA Total Security to the latest version provided by the vendor.
Who is affected by ZDI-25-590?
All installations of G DATA Total Security that are vulnerable to local privilege escalation are affected by ZDI-25-590.
What is the potential impact of ZDI-25-590?
The potential impact of ZDI-25-590 includes unauthorized access to sensitive system resources by local attackers.
Is there a workaround for ZDI-25-590?
Currently, there are no documented workarounds for ZDI-25-590, and applying the update is recommended for mitigation.