G DATA Total Security G DATA Tuner link following local privilege escalation vulnerability CVE-2025-2790

Overview

Advisory ID: GD-2025-0001
Reporting date: 2025-03-12T12:53:00.000Z
Advisory date: 2026-07-06T10:31:00.000Z
Last Updated: 2026-09-18T11:15:00.000Z
CVE number: CVE-2025-2790
Severity rating: CRITICAL
CVSS score: 7.8
TLP Rating: CLEAR

G DATA Total Security G DATA Tuner link following arbitrary file deletion vulnerability which allows to a local privilege escalation.

Products involved

Product(s) Version(s) Component(s) Operating system(s)

G DATA Total Security

25.5.18.333

G DATA Tuner

Windows

Vulnerability description

By moving and deleting files associated with the service for the G DATA Tuner it was possible to escalate permissions using a link-following attack.

Mitigation solution

Update your product to version 25.5.19.439 or higher. This version was released on the 01/07/2025. You can either trigger the automated update process within the program explained here or re-install it using the latest Version using the direct download link https://secure.gd/dl-ts.

References and acknowledgements

Zero Day Initiative advisory ZDI-25-590. We would like to thank Hao Huang in conjunction with Trend Micro’s Zero Day Initiative for reporting this issue to us.