Untrusted Search Path Vulnerability in Bitdefender Antivirus Free 2020
CVE-2020-8094

8.8HIGH

Key Information:

Vendor
Bitdefender
Status
Antivirus Free 2020
Vendor
CVE Published:
15 January 2025

Summary

A vulnerability exists in Bitdefender Antivirus Free 2020 due to an untrusted search path in the testinitsigs.exe process. This flaw allows a low-privilege attacker to exploit the system by executing malicious code with SYSTEM privileges by leveraging a specially crafted DLL file. This security loophole can enable unauthorized access and manipulation of sensitive system-level operations.

Affected Version(s)

Antivirus Free 2020 0 < 1.0.16.152

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gábor Selján
.