Home

Description

A local privilege escalation vulnerability in Bitdefender Total Security 27.0.46.231 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user.

PUBLISHED Reserved 2025-07-04 | Published 2025-12-10 | Updated 2025-12-10 | Assigner Bitdefender




HIGH: 8.8CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-59 Improper Link Resolution Before File Access ('Link Following')

Product status

Default status
unaffected

Any version before 27.10.45.497
affected

Default status
unaffected

Any version before 27.10.45.497
affected

Default status
unaffected

Any version before 27.10.45.497
affected

Credits

Filip Dragovic (@filip_dragovic) finder

References

www.bitdefender.com/...operation-in-bitdefender-atc-va-12590

cve.org (CVE-2025-7073)

nvd.nist.gov (CVE-2025-7073)

Download JSON