CVE-2020-8093: Code Injection into Bitdefender AV for Mac
A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a library using DYLD environment variable to cause third-party code execution
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bitdefender Antivirus for Mac (AntivirusforMac)to a version that resolves this vulnerability.Fixed in 8.0.0
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-8093.
What software is affected by this vulnerability?
The Bitdefender Antivirus for Mac version up to 8.0.0 is affected by this vulnerability.
What is the severity of CVE-2020-8093?
The severity of CVE-2020-8093 is high with a CVSS score of 7.8.
How can an attacker exploit CVE-2020-8093?
An attacker can exploit CVE-2020-8093 by injecting a library using the DYLD environment variable to cause third-party code execution.
Is there a fix available for CVE-2020-8093?
Yes, Bitdefender has released a fix for CVE-2020-8093. It is recommended to update to the latest version of Bitdefender Antivirus for Mac.