Impact
An improper link resolution before file access in the File Shredder module allows a less‑privileged local user to create or manipulate symbolic links, triggering a race condition that can cause the program to access unintended files. This flaw is categorized as CWE‑59 and can lead to elevation of privileges or modification of protected files, compromising the integrity of the system.
Affected Systems
Bitdefender Internet Security and Bitdefender Total Security on Windows, any version prior to 27.0.58.315, are affected. Users running these versions are vulnerable to the race‑condition attack described.
Risk and Exploitability
The vulnerability carries a CVSS score of 7, indicating a high impact if exploited. An EPSS score of less than 1% implies that exploitation is unlikely at present, and it is not listed in the CISA KEV catalog. The attack vector is local, relying on a user who can create symbolic links within the system; without a publicly documented exploit, the risk for unpatched systems remains moderate but should be mitigated promptly.
OpenCVE Enrichment