CVE-2020-15731: Local Privilege Escalation in Bitdefender Engines (VA-8953)
An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name. This issue affects: Bitdefender Engines versions prior to 7.85448.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-15731?
CVE-2020-15731 is an improper Input Validation vulnerability in Bitdefender Engines that allows an attacker to write an arbitrary file.
How does CVE-2020-15731 affect Bitdefender Engines?
CVE-2020-15731 affects Bitdefender Engines versions prior to 7.85448.
What is the severity of CVE-2020-15731?
CVE-2020-15731 is classified as a medium severity vulnerability with a severity value of 3.6.
How can an attacker exploit CVE-2020-15731?
An attacker can exploit CVE-2020-15731 by using a specially-crafted malicious file name to write an arbitrary file in a hardcoded location.
Is there a fix for CVE-2020-15731?
Yes, the fix for CVE-2020-15731 is to update Bitdefender Engines to version 7.85448 or later.