Vulnerability Name: | CVE-2017-10950 (CCN-130583) | ||||||||||||
Assigned: | 2017-08-17 | ||||||||||||
Published: | 2017-08-17 | ||||||||||||
Updated: | 2019-10-09 | ||||||||||||
Summary: | This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within processing of the 0x8000E038 IOCTL in the bdfwfpf driver. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker could leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4776. | ||||||||||||
CVSS v3 Severity: | 7.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-415 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-10950 Source: BID Type: Third Party Advisory, VDB Entry 100418 Source: CCN Type: BID-100418 Bitdefender Total Security CVE-2017-10950 Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWN bitdefender-cve201710950-priv-esc(130583) Source: CCN Type: Bitdefender Web site Cybersecurity Solutions for Business and Personal Use Source: CCN Type: ZDI-17-693 Bitdefender Total Security bdfwfpf Kernel Driver Double Free Privilege Escalation Vulnerability Source: MISC Type: Third Party Advisory, VDB Entry https://zerodayinitiative.com/advisories/ZDI-17-693 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |