First published: Mon Jan 27 2020(Updated: )
An Untrusted Search Path vulnerability in EPSecurityService.exe as used in Bitdefender Endpoint Security Tools versions prior to 6.6.11.163 allows an attacker to load an arbitrary DLL file from the search path. This issue affects: Bitdefender EPSecurityService.exe versions prior to 6.6.11.163.
Credit: cve-requests@bitdefender.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bitdefender Endpoint Security Tools | <6.6.11.163 |
Automatic update to version 6.6.11.163 mitigates the issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17099 is an Untrusted Search Path vulnerability in EPSecurityService.exe as used in Bitdefender Endpoint Security Tools versions prior to 6.6.11.163.
The severity of CVE-2019-17099 is high with a CVSS score of 7.8.
CVE-2019-17099 allows an attacker to load an arbitrary DLL file from the search path in Bitdefender Endpoint Security Tools versions prior to 6.6.11.163.
To fix CVE-2019-17099, update Bitdefender Endpoint Security Tools to version 6.6.11.163 or later.
You can find more information about CVE-2019-17099 on the Bitdefender website at the following link: [Untrusted Search Path Vulnerability in EPSecurityService.exe](https://www.bitdefender.com/support/security-advisories/untrusted-search-path-vulnerability-epsecurityservice-exe-va-3500/).