CVE-2026-13268: Local Privilege Escalation in G DATA Total Security Backup Service
What It Is — A newly disclosed vulnerability (CVE‑2026‑13268) in the Backup Service component of G DATA Total Security allows a local attacker to create a malicious symbolic link that deletes arbitrary files and escalates privileges to SYSTEM.
Exploitability — The flaw is exploitable by any attacker who can run low‑privileged code on the host; a proof‑of‑concept exists in the ZDI advisory. CVSS 7.8 (High) – AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Affected Products — G DATA Total Security (all versions prior to 25.5.20.121).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Controls (CC6.1/CC6.2): Privilege‑escalation defeats least‑privilege safeguards, a core audit criterion.
- Patch Management Evidence: Demonstrating timely remediation is essential for continuous compliance reporting.
- Audit Trail of Controls: Mapping this vulnerability to your access‑control policies provides defensible evidence during a SOC 2 audit.
Recommended Actions
- Deploy the vendor‑provided fix (version 25.5.20.121) immediately.
- Review and harden file‑system permissions for the Backup Service to prevent symlink abuse.
- Update your SOC 2 access‑control documentation (CC6.1/CC6.2) with patch‑status evidence.
- Conduct a privileged‑access review to confirm no lingering low‑priv accounts can reach SYSTEM.