An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-29005 An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file.
Fixes

Solution

The vulnerability was fixed in Bitdefender Antivirus Free version 1.0.16.152. The fix has been automatically applied to affected instances.


Workaround

No workaround given by the vendor.

History

Fri, 07 Feb 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Bitdefender
Bitdefender antivirus 2020
CPEs cpe:2.3:a:bitdefender:antivirus_2020:*:*:*:*:free:*:*:*
Vendors & Products Bitdefender
Bitdefender antivirus 2020
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 15 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jan 2025 16:30:00 +0000

Type Values Removed Values Added
Description An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file.
Title Untrusted Search Path Vulnerability in Bitdefender Antivirus Free 2020 (VA-8422)
Weaknesses CWE-426
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Bitdefender

Published:

Updated: 2025-01-15T16:48:23.541Z

Reserved: 2020-01-28T00:00:00.000Z

Link: CVE-2020-8094

cve-icon Vulnrichment

Updated: 2025-01-15T16:47:34.075Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-15T17:15:09.810

Modified: 2025-02-07T21:07:34.963

Link: CVE-2020-8094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.