Bitdefender Napoca Out-of-Bounds Write Vulnerability in Real-Mode Hook Handler

Vulnerability

An out-of-bounds write vulnerability has been identified in the Bitdefender Napoca bare-metal hypervisor. This issue arises in the real-mode hook handler, where a guest-controlled SS:SP-derived offset is used to index into the 1MB RealModeMemory buffer without proper bounds validation. With specific values for SS and ESP, the offset can exceed the buffer limit, allowing the IRET frame push to write into the hypervisor heap. This vulnerability is present in a product that is end-of-life and no longer supported.

Impact

Exploitation of this vulnerability allows for an out-of-bounds write, where data can be written past the end of the RealModeMemory buffer into the hypervisor heap. This type of vulnerability can potentially be exploited to manipulate memory in a way that leads to arbitrary code execution or other malicious outcomes.

Remediation

No fix is planned for this vulnerability, as Bitdefender Napoca is no longer supported. Users are advised to discontinue use of the product.

Added: Jun 2, 2026, 4:54 PM
Updated: Jun 2, 2026, 4:54 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.