VendorsBitdefenderantivirus_plusany version
Vulnerabilities

Bitdefender Antivirus Plus any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2025-7073
Local Privilege Escalation via Arbitrary File Operation in Bitdefender Total Security
Published 2025-12-10 · Analyzed
8.8EPSS 0.002
CVE-2020-8107
Process Control vulnerability in Bitdefender Antivirus Plus
Published 2022-02-18 · Modified
8.2EPSS 0.003
CVE-2021-4199
Incorrect Permission Assignment for Critical Resource vulnerability in BDReinit.exe (VA-10017)
Published 2022-03-07 · Modified
7.8EPSS 0.008
CVE-2022-0357
Improper Quoting Path Issue in Bitdefender Total Security
Published 2023-05-24 · Modified
7.8EPSS 0.002
CVE-2020-15732
Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security versions prior to 25.0.7.29. Bitdefender Antivirus Plus versions prior to 25.0.7.29.
Published 2021-06-22 · Modified
7.5EPSS 0.005
CVE-2017-6186
Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Bitdefender process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.
Published 2017-03-21 · Modified
7.2EPSS 0.008
CVE-2019-14242
An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with administrator privileges can create a malicious DLL file in %SystemRoot%\System32\ that will be executed with local user privileges.
Published 2019-07-30 · Modified
7.2EPSS 0.006
CVE-2020-15733
URL Spoofing Vulnerability in Bitdefender SafePay (VA-8958)
Published 2020-12-14 · Modified
6.5EPSS 0.006
CVE-2021-4198
messaging_ipc.dll NULL Pointer Dereference in multiple Bitdefender products (VA-10016)
Published 2022-03-07 · Modified
6.1EPSS 0.006