PT-2025-1350 · Bitdefender · Bitdefender Antivirus Free 2020

·

CVE-2020-8094

·

Published

2025-01-15

·

Updated

2025-01-15

CVSS v4.0

8.8

High

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Bitdefender Antivirus Free 2020
Description An untrusted search path vulnerability in testinitsigs.exe allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file. This issue enables an attacker to gain elevated privileges.
Recommendations For Bitdefender Antivirus Free 2020, update to a version that includes a fix for this issue, as using a specially crafted DLL file can lead to code execution with SYSTEM privileges. As a temporary workaround, consider restricting access to the testinitsigs.exe file to minimize the risk of exploitation.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8094

Affected Products

Bitdefender Antivirus Free 2020