Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in execution by the SetupSVC.exe service in the context of SYSTEM.
CVE ID: CVE-2025-0543
CVSS Base Severity: HIGH
CVSS Base Score: 8.5
Vendor: G DATA CyberDefense AG
Product: G DATA Security Client
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.72% (scored less or equal to compared to others)
EPSS Date: 2025-02-23 (when was this score calculated)