Arbitrary File Write as SYSTEM via Mount Point and Symlink in G DATA Internet Security for Windows not available

Overview

Advisory ID: GD-2025-0002
Reporting date: 2025-05-13T15:03:31.000Z
Advisory date: 2026-08-13T15:03:00.000Z
Last Updated: 2026-09-18T11:15:00.000Z
CVE number: not available
Severity rating: HIGH
CVSS score: not available
TLP Rating: CLEAR

A local privilege escalation vulnerability. Arbitrary File Write as SYSTEM via Mount Point and Symlink in G DATA Internet Security for Windows.

Products involved

Product(s) Version(s) Component(s) Operating system(s)

G DATA Internet Security

25.5.18.001

G DATA Internet Security

Windows

Vulnerability description

A local privilege escalation vulnerability exists in the G DATA Internet Security for Windows installer due to an improperly secured write to C:\ProgramData\G DATA\AVKProxy\GDStatistics.json during installation. A low-privileged attacker can exploit this behavior by pre-creating the G DATA directory and setting up a mount point to \RPC Control, followed by a symbolic link redirecting GDStatistics.json to an arbitrary location such as C:\Windows\System32\evil.dll.

Mitigation solution

Install program version v25.5.19.439 or higher to fix this issue. You can get the latest version of G DATA Internet Security via this download link.

References and acknowledgements

We would like to thank Sheikh Rishad for reporting this issue to us.