CVE-2024-2224: Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component:
Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2224?
CVE-2024-2224 has a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2024-2224?
To fix CVE-2024-2224, users should update their Bitdefender products to the latest patched versions.
Which products are affected by CVE-2024-2224?
CVE-2024-2224 affects Bitdefender Endpoint Security versions 7.0.5.200089 and 7.9.9.380, as well as Bitdefender GravityZone Control Center version 6.36.1.
What type of vulnerability is CVE-2024-2224?
CVE-2024-2224 is classified as a Path Traversal vulnerability that can lead to privilege escalation.
Can CVE-2024-2224 be exploited remotely?
Yes, CVE-2024-2224 can be exploited by attackers remotely if the vulnerable software is accessible.