CVE-2019-17099
Published on: 01/27/2020 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:27:38 PM UTC
Certain versions of Endpoint Security Tools from Bitdefender contain the following vulnerability:
An Untrusted Search Path vulnerability in EPSecurityService.exe as used in Bitdefender Endpoint Security Tools versions prior to 6.6.11.163 allows an attacker to load an arbitrary DLL file from the search path. This issue affects: Bitdefender EPSecurityService.exe versions prior to 6.6.11.163.
- CVE-2019-17099 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Bitdefender - EPSecurityService.exe version 6.6.11.162 and prior
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 4.4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Untrusted Search Path vulnerability in EPSecurityService.exe (VA-3500) - Bitdefender | Vendor Advisory www.bitdefender.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Bitdefender | Endpoint Security Tools | All | All | All | All |
Application | Bitdefender | Endpoint Security Tools | All | All | All | All |
- cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:*:*:*:
- cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:*:*:*:
Discovery Credit
Bugcrowd user khangkito