CNNVD-202512-1995 Information

CNNVD ID

CNNVD-202512-1995

CVE-2025-7073

  • CNNVD Published: 2025-12-10

Description (Chinese)

Bitdefender Total Security是罗马尼亚比特梵德(Bitdefender)公司的一款应用于PC端的主动威胁防护软件。该软件具有防病毒,防火墙,反间谍软件,隐私控制,家长控制功能。还包括System TuneUp等功能。 Bitdefender Total Security 27.0.46.231版本存在后置链接漏洞,该漏洞源于符号链接验证不足,可能导致任意文件删除和权限提升。

Description (English)

Bitdefender Total Security is an active threat protection software for the PC end of the company Bitdefender in Romania. The software has anti-virus, firewalls, anti-spy software, privacy control and parental control. It also includes features such as Systems TuneUP. There is a post-link loophole in Bitdefender Total Security 27.0.46.231, which results from inadequate symbol link authentication, which may lead to any deletion of documents and the increase in privileges.

Hazard Level

High

Vulnerability Type

后置链接

Affected Vendor

比特梵德

Published

2025-12-10

Last Modified

2026-02-24

References

https://www.bitdefender.com/support/security-advisories/local-privilege-escalation-via-arbitrary-file-operation-in-bitdefender-atc-va-12590

Patch

https://www.bitdefender.com/support/security-advisories/local-privilege-escalation-via-arbitrary-file-operation-in-bitdefender-atc-va-12590

Share on: