CVE-2025-2244: Insecure PHP deserialization issue in GravityZone Console (VA-12634)
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger PHP object injection, perform a file write, and gain arbitrary command execution on the host system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2244?
CVE-2025-2244 is considered a critical vulnerability due to the potential for remote code execution through PHP object injection.
How do I fix CVE-2025-2244?
To fix CVE-2025-2244, update to the latest version of Bitdefender GravityZone Console that contains the security patch addressing this vulnerability.
What impact does CVE-2025-2244 have on my system?
CVE-2025-2244 can allow attackers to execute arbitrary PHP code, leading to unauthorized access and control over the affected server.
Is CVE-2025-2244 easy to exploit?
Yes, CVE-2025-2244 can be easily exploited by an attacker who provides a malicious serialized payload to the vulnerable method.
Which versions of Bitdefender GravityZone Console are affected by CVE-2025-2244?
CVE-2025-2244 affects all versions of Bitdefender GravityZone Console prior to the release of the patch that mitigates this issue.