CVE-2021-3576: Bitdefender GravityZone Unnecessary Privileges Local Privilege Escalation Vulnerability
Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a local attacker to elevate to 'NT AUTHORITY\System. Impersonation enables the server thread to perform actions on behalf of the client but within the limits of the client's security context. This issue affects: Bitdefender Endpoint Security Tools versions prior to 7.2.1.65. Bitdefender Total Security versions prior to 25.0.26.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Bitdefender GravityZone. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the endpoint client. The issue results from allowing an untrusted process to impersonate the client of a pipe. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
— ZDI
This vulnerability allows local attackers to escalate privileges on affected installations of Bitdefender Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the endpoint client. The issue results from allowing an untrusted process to impersonate the client of a pipe. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-3576?
CVE-2021-3576 is a vulnerability that allows local attackers to escalate privileges on affected installations of Bitdefender Total Security.
How does CVE-2021-3576 work?
CVE-2021-3576 allows an attacker to execute low-privileged code on the target system and exploit a flaw within the endpoint security tools of Bitdefender Total Security.
What is the severity of CVE-2021-3576?
CVE-2021-3576 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2021-3576?
CVE-2021-3576 affects Bitdefender Endpoint Security Tools version up to 7.2.1.65 and Bitdefender Total Security version up to 25.0.26.
How can I mitigate the risk of CVE-2021-3576?
To mitigate the risk of CVE-2021-3576, ensure that you have installed the latest updates and patches from Bitdefender.