CVE-2020-8103: Link Resolution Privilege Escalation Vulnerability in Bitdefender Antivirus Free (VA-8604)
Published Jun 5, 2020
·Updated
A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects Bitdefender Antivirus Free versions prior to 1.0.17.178.
Affected Software
1 affected component
Bitdefender Antivirus 2020<1.0.17.178
Remediation
Information
An automatic update to Bitdefender Antivirus Free version 1.0.17.178 or newer fixes the issue.
Event History
Jun 5, 2020
CVE Published
via MITRE·11:10 AM
Data Sourced
via MITRE·11:10 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-8103?
CVE-2020-8103 is a vulnerability in Bitdefender Antivirus Free that allows an unprivileged user to substitute a quarantined file and restore it to a privileged location.
2
Which versions of Bitdefender Antivirus Free are affected by CVE-2020-8103?
Bitdefender Antivirus Free versions prior to 1.0.17.178 are affected by CVE-2020-8103.
3
How severe is CVE-2020-8103?
CVE-2020-8103 has a severity rating of 7.1 (high).
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-8103?
The CWE ID for CVE-2020-8103 is CWE-59.
5
How can I fix CVE-2020-8103?
To fix CVE-2020-8103, users should update to Bitdefender Antivirus Free version 1.0.17.178 or later.