Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2020-8095 |
CWE-ID | CWE-20 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
Bitdefender Total Security Client/Desktop applications / Antivirus software/Personal firewalls |
Vendor | Bitdefender |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU24802
Risk: Low
CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2020-8095
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of junctions before deletion. An authenticated attacker with physical access can trigger a denial of service condition on the affected device.
MitigationInstall updates from vendor's website.
Vulnerable software versionsBitdefender Total Security: before 24.9
CPE2.3 External linksQ & A
Can this vulnerability be exploited remotely?
No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.