CVE-2021-3641: Bitdefender GravityZone Link Following Denial-of-Service Vulnerability
Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows allows a local attacker to cause a denial of service. This issue affects: Bitdefender GravityZone version 7.1.2.33 and prior versions.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Bitdefender GravityZone. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Endpoint Agent. By creating a symbolic link, an attacker can abuse the service to overwrite a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-3641?
CVE-2021-3641 is a vulnerability that allows local attackers to create a denial-of-service condition on affected installations of Bitdefender GravityZone.
How do attackers exploit CVE-2021-3641?
To exploit CVE-2021-3641, attackers must first obtain the ability to execute low-privileged code on the target system.
Which software is affected by CVE-2021-3641?
CVE-2021-3641 affects Bitdefender GravityZone versions up to 7.1.2.33.
How severe is CVE-2021-3641?
CVE-2021-3641 has a severity score of 6.1 (medium).
How can I fix CVE-2021-3641?
To fix CVE-2021-3641, it is recommended to update Bitdefender GravityZone to the latest version available.