CVE-2024-2224
Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component:
Bitdefender Endpoint Security for Linux version 7.0.5.200089
Bitdefender Endpoint Security for Windows version 7.9.9.380
GravityZone Control Center (On Premises) version 6.36.1
La vulnerabilidad de limitación inadecuada de un nombre de ruta a un directorio restringido ("Path Traversal") en el componente UpdateServer de Bitdefender GravityZone permite a un atacante ejecutar código arbitrario en instancias vulnerables. Este problema afecta a los siguientes productos que incluyen el componente vulnerable: Bitdefender Endpoint Security para Linux versión 7.0.5.200089 Bitdefender Endpoint Security para Windows versión 7.9.9.380 GravityZone Control Center (On Premises) versión 6.36.1
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-03-06 CVE Reserved
- 2024-04-09 CVE Published
- 2024-04-21 EPSS Updated
- 2024-05-20 First Exploit
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
- CAPEC-21: Exploitation of Trusted Identifiers
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bitdefender Search vendor "Bitdefender" | GravityZone Control Center (On Premises) Search vendor "Bitdefender" for product "GravityZone Control Center (On Premises)" | 6.36.1 Search vendor "Bitdefender" for product "GravityZone Control Center (On Premises)" and version "6.36.1" | en |
Affected
| ||||||
Bitdefender Search vendor "Bitdefender" | Endpoint Security For Windows Search vendor "Bitdefender" for product "Endpoint Security For Windows" | 7.9.9.380 Search vendor "Bitdefender" for product "Endpoint Security For Windows" and version "7.9.9.380" | en |
Affected
| ||||||
Bitdefender Search vendor "Bitdefender" | Endpoint Security For Linux Search vendor "Bitdefender" for product "Endpoint Security For Linux" | 7.0.5.200089 Search vendor "Bitdefender" for product "Endpoint Security For Linux" and version "7.0.5.200089" | en |
Affected
|