CVE-2019-15295
Summary
| CVE | CVE-2019-15295 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-21 18:15:00 UTC |
| Updated | 2019-08-28 15:54:00 UTC |
| Description | An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, allows an attacker to load an arbitrary DLL file from the search path. |
Risk And Classification
Problem Types: CWE-426
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bitdefender | Antivirus 2020 | All | All | All | All |
| Application | Bitdefender | Antivirus 2020 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BitDefender Antivirus Free 2020 - Privilege Escalation to SYSTEM | MISC | safebreach.com | Third Party Advisory |
| Untrusted Search Path vulnerability in ServiceInstance.dll (Bitdefender Antivirus Free 2020) - Bitdefender | CONFIRM | www.bitdefender.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.