CVE-2019-15295: Critical severity bitdefender antivirus vulnerability
An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, allows an attacker to load an arbitrary DLL file from the search path.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15295?
CVE-2019-15295 is an Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138.
How does CVE-2019-15295 affect Bitdefender Antivirus Free 2020?
CVE-2019-15295 allows an attacker to load an arbitrary DLL file from the search path, potentially leading to privilege escalation on Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138.
What is the severity of CVE-2019-15295?
CVE-2019-15295 has a severity value of 7.8, which is considered critical.
How can I fix CVE-2019-15295?
To fix CVE-2019-15295, update Bitdefender Antivirus Free 2020 to version 1.0.15.138 or later.
Where can I find more information about CVE-2019-15295?
You can find more information about CVE-2019-15295 at the following references: [SafeBreach](https://safebreach.com/Post/BitDefender-Antivirus-Free-2020-Privilege-Escalation-to-SYSTEM) and [Bitdefender Security Advisories](https://www.bitdefender.com/support/security-advisories/untrusted-search-path-vulnerability-serviceinstance-dll-bitdefender-antivirus-free-2020/).