ZDI-19-159: Bitdefender SafePay launch Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of TIScript. When processing the launch method the application does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-19-159?
The severity of ZDI-19-159 is critical due to its potential for remote code execution.
How do I fix ZDI-19-159?
To fix ZDI-19-159, users should update their Bitdefender SafePay to the latest version provided by the vendor.
What types of attacks can exploit ZDI-19-159?
ZDI-19-159 can be exploited by remote attackers through malicious web pages or files that require user interaction.
Who is affected by ZDI-19-159?
ZDI-19-159 affects installations of Bitdefender SafePay that are not updated to the patched versions.
Are there any workarounds for ZDI-19-159?
Currently, the best workaround for ZDI-19-159 is to avoid opening suspicious files or visiting unknown websites until the software is updated.