First published: Tue Jul 30 2019(Updated: )
An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with administrator privileges can create a malicious DLL file in %SystemRoot%\System32\ that will be executed with local user privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bitdefender Antivirus Plus | <23.0.24.120 | |
Bitdefender Endpoint Security Tool | <6.6.8.115 | |
BitDefender Internet Security | <23.0.24.120 | |
Bitdefender Total Security | <23.0.24.120 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14242 is an issue discovered in Bitdefender products for Windows that can lead to local code injection.
Bitdefender Endpoint Security Tool versions prior to 6.6.8.115 and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120 are affected.
CVE-2019-14242 has a severity rating of 6.7, which is considered high.
CVE-2019-14242 allows an attacker to inject malicious code locally on the affected system.
To fix CVE-2019-14242, update your Bitdefender products to version 6.6.8.115 for Bitdefender Endpoint Security Tool and version 23.0.24.120 for Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security.