Description
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component:

Bitdefender Endpoint Security for Linux version 7.0.5.200089
Bitdefender Endpoint Security for Windows version 7.9.9.380
GravityZone Control Center (On Premises) version 6.36.1
Published: 2024-04-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

An automatic update to the following versions fixes the issues: Bitdefender Endpoint Security for Linux version 7.0.5.200090 Bitdefender Endpoint Security for Windows version 7.9.9.381 GravityZone Control Center (On Premises) version 6.36.1-1

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-27180 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1
History

Fri, 07 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Bitdefender
Bitdefender endpoint Security
Bitdefender gravityzone Control Center
CPEs cpe:2.3:a:bitdefender:endpoint_security:7.0.5.200089:*:*:*:*:linux:*:*
cpe:2.3:a:bitdefender:endpoint_security:7.9.9.380:*:*:*:*:windows:*:*
cpe:2.3:a:bitdefender:gravityzone_control_center:6.36.1:*:*:*:on_premises:*:*:*
Vendors & Products Bitdefender
Bitdefender endpoint Security
Bitdefender gravityzone Control Center

Subscriptions

Bitdefender Endpoint Security Gravityzone Control Center
cve-icon MITRE

Status: PUBLISHED

Assigner: Bitdefender

Published:

Updated: 2024-08-01T19:03:39.266Z

Reserved: 2024-03-06T14:44:03.507Z

Link: CVE-2024-2224

cve-icon Vulnrichment

Updated: 2024-08-01T19:03:39.266Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-09T13:15:33.357

Modified: 2025-02-07T18:53:18.953

Link: CVE-2024-2224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses