PT-2021-21269 · Bitdefender · Bitdefender Gravityzone+1

Kharosx0

·

Published

2021-11-09

·

Updated

2022-02-09

·

CVE-2021-3641

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Bitdefender GravityZone versions 7.1.2.33 and prior versions
Description The issue is related to an Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows. This allows a local attacker to cause a denial of service.
Recommendations For Bitdefender GravityZone versions 7.1.2.33 and prior versions, update to a version later than 7.1.2.33 to resolve the issue. As a temporary workaround, consider restricting access to the EPAG component until a patch is available.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3641
ZDI-22-143

Affected Products

Bitdefender Endpoint Security Tools
Bitdefender Gravityzone