QID 376073

QID 376073: Bitdefender Incorrect Default Permissions Vulnerability(VA-9848)

Bitdefender Endpoint Security Tool protects Windows target.

Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security Tools for Windows.

Affected Product:
Bitdefender Endpoint Security Tools for Windows versions prior to 7.2.1.65.
Bitdefender Total Security versions prior to 7.2.1.65.

This vulnerability causes local attacker to elevate privileges to NT AUTHORITY\SYSTEM.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Vendor has released a fix for this. For more information refer here.

    CVEs related to QID 376073

    Software Advisories
    Advisory ID Software Component Link
    VA-9848 Windows URL Logo www.bitdefender.com/support/security-advisories/incorrect-default-permissions-vulnerability-in-bdservicehost-exe-and-vulnerability-scan-exe-va-9848/