First published: Tue Apr 26 2005(Updated: )
Unquoted Windows search path vulnerability in BitDefender 8 allows local users to prevent BitDefender from starting by creating a malicious C:\program.exe, possibly due to the lack of quoting of the full pathname when executing a process.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
softwin BitDefender antivirus | =professional_plus_8 | |
softwin BitDefender antivirus | =standard_8 | |
Bitdefender Antivirus | =professional_plus_8 | |
Bitdefender Antivirus | =standard_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1286 is classified as a moderate severity vulnerability because it allows local users to disrupt the execution of BitDefender.
To fix CVE-2005-1286, ensure that the installation path for BitDefender is properly quoted in the execution command to prevent local path manipulation.
CVE-2005-1286 affects BitDefender Professional Plus 8 and BitDefender Standard 8.
CVE-2005-1286 facilitates a local privilege escalation attack by allowing users to create a malicious executable that prevents BitDefender from launching.
While specific exploit code for CVE-2005-1286 is not commonly documented, the vulnerability can be reproduced by creating a malicious executable at the specified path.