First published: Wed Aug 21 2019(Updated: )
An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, allows an attacker to load an arbitrary DLL file from the search path.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bitdefender Antivirus 2020 | <1.0.15.138 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15295 is an Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138.
CVE-2019-15295 allows an attacker to load an arbitrary DLL file from the search path, potentially leading to privilege escalation on Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138.
CVE-2019-15295 has a severity value of 7.8, which is considered critical.
To fix CVE-2019-15295, update Bitdefender Antivirus Free 2020 to version 1.0.15.138 or later.
You can find more information about CVE-2019-15295 at the following references: [SafeBreach](https://safebreach.com/Post/BitDefender-Antivirus-Free-2020-Privilege-Escalation-to-SYSTEM) and [Bitdefender Security Advisories](https://www.bitdefender.com/support/security-advisories/untrusted-search-path-vulnerability-serviceinstance-dll-bitdefender-antivirus-free-2020/).