G DATA Security Client Local privilege escalation
Vulnerability Description
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in execution by the SetupSVC.exe service in the context of SYSTEM.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0543
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Fabian Duschek
More from G DATA CyberDefense AG
View All →Affected Vendor
G DATA CyberDefense AG
View all reports →