CRITICAL🇵🇱 Wersja polska

CVE-2025-2244

CVSS 9.5v4.0pub. 2025-04-04upd. 2025-07-30

A vulnerability in the sendMailFromRemoteSource method in Emails.php  as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger PHP object injection, perform a file write, and gain arbitrary command execution on the host system.

🤖 AI Analysis
How it works

The application calls the PHP unserialize() function on user-supplied data without any validation of its correctness or security. An attacker can craft a malicious, properly formatted serialized payload and submit it to the vulnerable method. This causes PHP object injection, which can subsequently be exploited to write files to the server. Arbitrary file writing ultimately enables execution of arbitrary system commands on the host.

Impact

An unauthenticated remote attacker can gain full control over the system hosting Bitdefender GravityZone Console, including executing arbitrary system commands with application process privileges. This can lead to complete compromise of the entire environment managed by the security console.

Mitigation & patch

Patches available from the vendor should be applied according to references (vendor advisory: VA-12634, available at bitdefender.com/support/security-advisories/insecure-php-deserialization-issue-in-gravityzone-console-va-12634)

Who is affected

Bitdefender GravityZone Console — versions specified in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Bitdefender Gravityzone

    APP
    Bitdefender
    < 6.41.2-1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2024-6980CRITICAL9.2PL ✓same product

SSRF przez błędną obsługę błędów w GravityZone Update Server

CVE-2021-3554CRITICAL9.0PL ✓same product

Nieprawidłowa kontrola dostępu w API patchesUpdate — Bitdefender Endpoint Security Tools

CVE-2017-8931CRITICAL9.8PL ✓same product

Nieautoryzowany dostęp z uprawnieniami root w Bitdefender GravityZone VMware

CVE-2018-8955CRITICAL9.8PL ✓same product

Bitdefender GravityZone – pominięcie weryfikacji podpisu i RCE przez instalator

CVE-2024-4177HIGH8.1same product

A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an atta...