CVE-2020-15279: Scanning exclusion paths disclosure in BEST for Windows
Published May 18, 2021
·Updated
An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during external security research.
Affected Software
1 affected component
Bitdefender Endpoint Security Tools Windows<6.6.23.320
Remediation
Information
An automatic update to version 6.6.23.320 fixes the issue.
Event History
May 18, 2021
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-15279.
2
What is the title of the vulnerability?
The title of the vulnerability is 'An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows'.
3
What is the severity of CVE-2020-15279?
CVE-2020-15279 has a severity level of medium.
4
How can a regular user exploit this vulnerability?
A regular user can exploit this vulnerability to learn the scanning exclusion paths.
5
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability. Users should update Bitdefender Endpoint Security Tools for Windows to version 6.6.23.320 or later.