CRITICAL🇵🇱 Wersja polska

CVE-2018-8955

CVSS 9.8v3.0pub. 2018-10-24upd. 2024-11-21

The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Bitdefender Gravityzone

    APP
    Bitdefender
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-2244CRITICAL9.5PL ✓same product

Niebezpieczna deserializacja PHP w Bitdefender GravityZone Console (RCE)

CVE-2024-6980CRITICAL9.2PL ✓same product

SSRF przez błędną obsługę błędów w GravityZone Update Server

CVE-2021-3554CRITICAL9.0PL ✓same product

Nieprawidłowa kontrola dostępu w API patchesUpdate — Bitdefender Endpoint Security Tools

CVE-2017-8931CRITICAL9.8PL ✓same product

Nieautoryzowany dostęp z uprawnieniami root w Bitdefender GravityZone VMware

CVE-2024-4177HIGH8.1same product

A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an atta...