No analysis available yet.
Vendor Solution
An automatic update to product version 27.0.47.241 fixes the issue
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 31 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A local privilege escalation vulnerability in Bitdefender Total Security 27.0.46.231 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user. | A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user. |
Mon, 12 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bitdefender antivirus
Bitdefender endpoint Security Tools |
|
| CPEs | cpe:2.3:a:bitdefender:antivirus:*:*:*:*:free:*:*:* cpe:2.3:a:bitdefender:antivirus_plus:*:*:*:*:*:*:*:* cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:windows:*:* cpe:2.3:a:bitdefender:internet_security:*:*:*:*:*:*:*:* cpe:2.3:a:bitdefender:total_security:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Bitdefender antivirus
Bitdefender endpoint Security Tools |
|
| Metrics |
cvssV3_1
|
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bitdefender
Bitdefender antivirus Plus Bitdefender internet Security Bitdefender total Security |
|
| Vendors & Products |
Bitdefender
Bitdefender antivirus Plus Bitdefender internet Security Bitdefender total Security |
Wed, 10 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A local privilege escalation vulnerability in Bitdefender Total Security 27.0.46.231 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user. | |
| Title | Local Privilege Escalation via Arbitrary File Operation in Bitdefender Total Security | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Bitdefender
Published:
Updated: 2026-03-31T11:43:59.146Z
Reserved: 2025-07-04T15:58:42.058Z
Link: CVE-2025-7073
Updated: 2025-12-10T16:53:15.070Z
Status : Modified
Published: 2025-12-10T10:16:02.330
Modified: 2026-03-31T12:16:26.993
Link: CVE-2025-7073
No data.
OpenCVE Enrichment
Updated: 2025-12-10T17:48:49Z