Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9247-4234-vwrq

Опубликовано: 10 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 7.8

Описание

A local privilege escalation vulnerability in Bitdefender Total Security 27.0.46.231 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user.

A local privilege escalation vulnerability in Bitdefender Total Security 27.0.46.231 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user.

EPSS

Процентиль: 5%
0.00021
Низкий

8.8 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
nvd
около 2 месяцев назад

A local privilege escalation vulnerability in Bitdefender Total Security 27.0.46.231 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user.

EPSS

Процентиль: 5%
0.00021
Низкий

8.8 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-59