Impact
An attacker can create a symbolic link that the G DATA Total Security Backup Service follows, allowing the deletion of arbitrary files. By abusing the service in this way, the attacker can elevate privileges from a low‑privileged user to SYSTEM and execute arbitrary code with full system rights. The weakness is a path‑traversal or symbolic‑link handling flaw (CWE‑59).
Affected Systems
The vulnerability affects installations of G DATA Total Security. No specific version information is provided, so all current installations are potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity flaw, yet the EPSS score of less than 1% suggests that exploitation is unlikely at present. It is not listed in the CISA KEV catalog. Exploitation requires local access and the ability to run low‑privileged code to create the malicious symbolic link; after that, the backup service deletes the target file and the attacker can trigger privilege escalation to SYSTEM.
OpenCVE Enrichment