Bitdefender Products Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in multiple Bitdefender products, including Total Security, Internet Security, Antivirus Plus, Antivirus Free, and Endpoint Security Tools for Windows. The vulnerability allows low-privileged attackers to elevate privileges by exploiting the Active Threat Control module. It arises from the 'bdservicehost.exe' process deleting files from a user-writable directory ('C:\ProgramData\Atc\Feedback') without proper validation of symbolic links, enabling arbitrary file deletion. This flaw is combined with a file copy operation during network events and a bypass of the filter driver through DLL injection, facilitating arbitrary file copying and code execution with elevated privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing low-privileged users to gain elevated rights and potentially execute code with those higher privileges.

Remediation

Bitdefender has released automatic updates to address this vulnerability. Users can update to the following versions: Bitdefender Total Security 27.10.45.497, Bitdefender Internet Security 27.10.45.497, Bitdefender Antivirus Plus 27.10.45.497, Bitdefender Antivirus Free 30.0.25.77, and Bitdefender Endpoint Security Tools for Windows 7.9.20.515.

Added: Dec 10, 2025, 10:17 AM
Updated: Dec 10, 2025, 10:17 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
2.9
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.