CVE-2020-8100: Incomplete validation in detection code in Bitdefender Engines (VA-8589)
Published May 15, 2020
·Updated
Improper Input Validation vulnerability in the cevakrnl.rv0 module as used in the Bitdefender Engines allows an attacker to trigger a denial of service while scanning a specially-crafted sample. This issue affects: Bitdefender Bitdefender Engines versions prior to 7.84063.
Affected Software
1 affected component
Bitdefender Engines<7.84063
Remediation
Information
An automatic update to engines version 7.84063 fixes the issue.
Event History
May 15, 2020
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-8100.
2
What is the severity rating of CVE-2020-8100?
CVE-2020-8100 has a severity rating of 7.5 (critical).
3
What software is affected by CVE-2020-8100?
CVE-2020-8100 affects Bitdefender Engines versions prior to 7.84063.
4
What is the impact of CVE-2020-8100?
CVE-2020-8100 allows an attacker to trigger a denial of service while scanning a specially-crafted sample.
5
Is there a fix available for CVE-2020-8100?
Yes, Bitdefender has released a fix for CVE-2020-8100. Please refer to the Bitdefender website for more information.