PT-2020-19946 · Bitdefender · Bitdefender Total Security 2020
Wladimir Palant
·
Published
2020-06-22
·
Updated
2020-06-26
·
CVE-2020-8102
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bitdefender Total Security 2020 versions prior to 24.0.20.116
Description
The issue is related to an Improper Input Validation vulnerability in the Safepay browser component, allowing an external, specially crafted web page to run remote commands inside the Safepay Utility process. This vulnerability can be exploited to achieve remote code execution (RCE) from any website. The vulnerability is not the first instance of a security flaw in antivirus software, as similar issues have been found in other antivirus products in the past.
Recommendations
For Bitdefender Total Security 2020 versions prior to 24.0.20.116, update to version 24.0.20.116 or later to resolve the issue. As a temporary workaround, consider restricting access to the Safepay browser component until the update is applied.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitdefender Total Security 2020