A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger PHP object injection, perform a file write, and gain arbitrary command execution on the host system.
The application calls the PHP unserialize() function on user-supplied data without any validation of its correctness or security. An attacker can craft a malicious, properly formatted serialized payload and submit it to the vulnerable method. This causes PHP object injection, which can subsequently be exploited to write files to the server. Arbitrary file writing ultimately enables execution of arbitrary system commands on the host.
An unauthenticated remote attacker can gain full control over the system hosting Bitdefender GravityZone Console, including executing arbitrary system commands with application process privileges. This can lead to complete compromise of the entire environment managed by the security console.
Patches available from the vendor should be applied according to references (vendor advisory: VA-12634, available at bitdefender.com/support/security-advisories/insecure-php-deserialization-issue-in-gravityzone-console-va-12634)
Bitdefender GravityZone Console — versions specified in vendor references
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBitdefender Gravityzone
APPBitdefender< 6.41.2-1
Related vulnerabilities
SSRF przez błędną obsługę błędów w GravityZone Update Server
Nieprawidłowa kontrola dostępu w API patchesUpdate — Bitdefender Endpoint Security Tools
Nieautoryzowany dostęp z uprawnieniami root w Bitdefender GravityZone VMware
Bitdefender GravityZone – pominięcie weryfikacji podpisu i RCE przez instalator
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an atta...