Vulnerability Name:

CVE-2017-10950 (CCN-130583)

Assigned:2017-08-17
Published:2017-08-17
Updated:2019-10-09
Summary:This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within processing of the 0x8000E038 IOCTL in the bdfwfpf driver. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker could leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4776.
CVSS v3 Severity:7.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.2 Medium (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-415
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2017-10950

Source: BID
Type: Third Party Advisory, VDB Entry
100418

Source: CCN
Type: BID-100418
Bitdefender Total Security CVE-2017-10950 Local Privilege Escalation Vulnerability

Source: XF
Type: UNKNOWN
bitdefender-cve201710950-priv-esc(130583)

Source: CCN
Type: Bitdefender Web site
Cybersecurity Solutions for Business and Personal Use

Source: CCN
Type: ZDI-17-693
Bitdefender Total Security bdfwfpf Kernel Driver Double Free Privilege Escalation Vulnerability

Source: MISC
Type: Third Party Advisory, VDB Entry
https://zerodayinitiative.com/advisories/ZDI-17-693

Vulnerable Configuration:Configuration 1:
  • cpe:/a:bitdefender:total_security:21.0.24.62:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:bitdefender:total_security:2010:13.0.20.347:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    bitdefender total security 21.0.24.62
    bitdefender bitdefender total security 2010 13.0.20.347