CVE-2019-9742: Gdata-Software Total Security
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\gdwfpcd device are not properly protected, leading to unintended impersonation or object creation.
Affected products
- Gdata-Software Total Security: before 2019-02-22 (fixed in 2019-02-22)
Published 2019-03-13. Last modified 2026-06-17.