CVE-2021-3423: Privilege escalation in Bitdefender GravityZone Business Security
Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Business Security versions prior to 6.6.23.329.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bitdefender GravityZone Business Securityto a version that resolves this vulnerability.Fixed in 6.6.23.329 - Compensating control
If immediate upgrade is not possible, prevent untrusted DLL loading by blocking write/execute permissions in any directories used as potential search-path elements for Bitdefender GravityZone Business Security (e.g., restrict write access and enforce least privilege on relevant folders).
Event History
Frequently Asked Questions
What is CVE-2021-3423?
CVE-2021-3423 is a vulnerability in the openssl component as used in Bitdefender GravityZone Business Security that allows an attacker to load a third party DLL to elevate privileges.
Which version of Bitdefender GravityZone Business Security is affected by CVE-2021-3423?
Bitdefender GravityZone Business Security versions prior to 6.6.23.329 are affected by CVE-2021-3423.
What is the severity of CVE-2021-3423?
CVE-2021-3423 has a severity rating of 7.8 (high).
How can an attacker exploit CVE-2021-3423?
An attacker can exploit CVE-2021-3423 by loading a third party DLL to elevate privileges.
Is there a fix available for CVE-2021-3423?
Yes, upgrading to Bitdefender GravityZone Business Security version 6.6.23.329 or later will fix CVE-2021-3423.