CVE-2021-4199

Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.3.146.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bitdefender:antivirus_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:windows:*:*
cpe:2.3:a:bitdefender:internet_security:*:*:*:*:*:*:*:*
cpe:2.3:a:bitdefender:total_security:*:*:*:*:*:*:*:*

History

11 Mar 2022, 18:52

Type Values Removed Values Added
First Time Bitdefender endpoint Security Tools
Bitdefender antivirus Plus
Bitdefender total Security
Bitdefender
Bitdefender internet Security
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
CPE cpe:2.3:a:bitdefender:total_security:*:*:*:*:*:*:*:*
cpe:2.3:a:bitdefender:internet_security:*:*:*:*:*:*:*:*
cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:windows:*:*
cpe:2.3:a:bitdefender:antivirus_plus:*:*:*:*:*:*:*:*
CWE CWE-732
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-22-484/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-22-484/ - Third Party Advisory
References (CONFIRM) https://www.bitdefender.com/support/security-advisories/incorrect-permission-assignment-for-critical-resource-vulnerability-in-bdreinit-exe-va-10017/ - (CONFIRM) https://www.bitdefender.com/support/security-advisories/incorrect-permission-assignment-for-critical-resource-vulnerability-in-bdreinit-exe-va-10017/ - Vendor Advisory

10 Mar 2022, 17:44

Type Values Removed Values Added
Summary Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.3.146. Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.3.146.
References
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-22-484/ -

07 Mar 2022, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-07 12:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-4199

Mitre link : CVE-2021-4199

CVE.ORG link : CVE-2021-4199


JSON object : View

Products Affected

bitdefender

  • total_security
  • antivirus_plus
  • internet_security
  • endpoint_security_tools
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource