PT-2024-2669 · Bitdefender · Bitdefender Internet Security+3

Published

2024-04-01

·

Updated

2025-02-07

·

CVE-2023-6154

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bitdefender Total Security version 27.0.25.114 Bitdefender Internet Security version 27.0.25.114 Bitdefender Antivirus Plus version 27.0.25.114 Bitdefender Antivirus Free version 27.0.25.114
Description A configuration setting issue in the seccenter.exe file used in Bitdefender products allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This could enable the attacker to elevate privileges or execute arbitrary code by loading a specially crafted library.
Recommendations For Bitdefender Total Security version 27.0.25.114, update to a newer version that contains a fix for this issue. For Bitdefender Internet Security version 27.0.25.114, update to a newer version that contains a fix for this issue. For Bitdefender Antivirus Plus version 27.0.25.114, update to a newer version that contains a fix for this issue. For Bitdefender Antivirus Free version 27.0.25.114, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the seccenter.exe file until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-02775
CVE-2023-6154

Affected Products

Bitdefender Antivirus Free
Bitdefender Antivirus Plus
Bitdefender Internet Security
Bitdefender Total Security