CVE-2005-1286: Low severity Softwin Bitdefender Antivirus vulnerability
Unquoted Windows search path vulnerability in BitDefender 8 allows local users to prevent BitDefender from starting by creating a malicious C:\program.exe, possibly due to the lack of quoting of the full pathname when executing a process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1286?
CVE-2005-1286 is classified as a moderate severity vulnerability because it allows local users to disrupt the execution of BitDefender.
How do I fix CVE-2005-1286?
To fix CVE-2005-1286, ensure that the installation path for BitDefender is properly quoted in the execution command to prevent local path manipulation.
Which versions of BitDefender are affected by CVE-2005-1286?
CVE-2005-1286 affects BitDefender Professional Plus 8 and BitDefender Standard 8.
What type of attack does CVE-2005-1286 facilitate?
CVE-2005-1286 facilitates a local privilege escalation attack by allowing users to create a malicious executable that prevents BitDefender from launching.
Is there any exploit code available for CVE-2005-1286?
While specific exploit code for CVE-2005-1286 is not commonly documented, the vulnerability can be reproduced by creating a malicious executable at the specified path.