CVE-2025-7073: Local Privilege Escalation via Arbitrary File Operation in Bitdefender Total Security
A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7073?
CVE-2025-7073 is rated as a high-severity local privilege escalation vulnerability in Bitdefender Total Security.
How do I fix CVE-2025-7073?
To fix CVE-2025-7073, ensure Bitdefender Total Security is updated to the latest version that addresses this vulnerability.
What does CVE-2025-7073 allow an attacker to do?
CVE-2025-7073 allows low-privileged users to elevate their privileges on affected systems.
Which version of Bitdefender Total Security is affected by CVE-2025-7073?
Bitdefender Total Security version 27.0.46.231 is affected by CVE-2025-7073.
What is the cause of CVE-2025-7073?
CVE-2025-7073 is caused by bdservicehost.exe improperly deleting files from a writable directory without proper symbolic link handling.