Privilege escalation in Bitdefender GravityZone Business Security
CVE-2021-3423

7.8HIGH

Key Information:

Vendor
CVE Published:
18 May 2021

What is CVE-2021-3423?

Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Business Security versions prior to 6.6.23.329.

Affected Version(s)

GravityZone Business Security < 6.6.23.329

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.