CVE-2018-8955: Critical severity bitdefender gravityzone vulnerability
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-8955?
CVE-2018-8955 is a vulnerability in the installer for BitDefender GravityZone that allows remote attackers to execute arbitrary code.
How does CVE-2018-8955 work?
CVE-2018-8955 relies on an encoded string in a filename to determine the URL for installation metadata, allowing attackers to change the filename while leaving the file's digital signature unchanged.
What is the severity of CVE-2018-8955?
The severity of CVE-2018-8955 is critical with a severity value of 9.8.
Which software is affected by CVE-2018-8955?
Bitdefender GravityZone is affected by CVE-2018-8955.
How can I fix CVE-2018-8955?
To fix CVE-2018-8955, apply the latest security patches and updates provided by BitDefender for GravityZone.