VendorsBitdefendertotal_securityall versions
Vulnerabilities

Bitdefender Total Security

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2007-5775
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
Published 2007-11-01 · Modified
9.81 PoCEPSS 0.269
CVE-2025-7073
Local Privilege Escalation via Arbitrary File Operation in Bitdefender Total Security
Published 2025-12-10 · Analyzed
8.8EPSS 0.002
CVE-2023-6055
Improper Certificate Validation in Bitdefender Total Security HTTPS Scanning (VA-11158)
Published 2024-10-18 · Analyzed
8.6EPSS 0.002
CVE-2023-6056
Insecure Trust of Self-Signed Certificates in Bitdefender Total Security HTTPS Scanning (VA-11164)
Published 2024-10-18 · Analyzed
8.6EPSS 0.002
CVE-2023-49570
Insecure Trust of Basic Constraints certificate in Bitdefender Total Security HTTPS Scanning (VA-11210)
Published 2024-10-18 · Analyzed
8.6EPSS 0.002
CVE-2023-6057
Insecure Trust of DSA-Signed Certificates in Bitdefender Total Security HTTPS Scanning (VA-11166)
Published 2024-10-18 · Modified
8.6EPSS 0.002
CVE-2023-6058
HTTPS Certificate Validation Issue in Bitdefender Safepay (VA-11167)
Published 2024-10-18 · Analyzed
8.6EPSS 0.002
CVE-2023-49567
Insecure Trust of certificates using collision hash functions in Bitdefender Total Security HTTPS Scanning (VA-11239)
Published 2024-10-18 · Analyzed
8.6EPSS 0.002
CVE-2020-8107
Process Control vulnerability in Bitdefender Antivirus Plus
Published 2022-02-18 · Modified
8.2EPSS 0.003
CVE-2021-3576
Privilege escalation via SeImpersonatePrivilege
Published 2021-10-28 · Modified
7.8EPSS 0.010
CVE-2021-4199
Incorrect Permission Assignment for Critical Resource vulnerability in BDReinit.exe (VA-10017)
Published 2022-03-07 · Modified
7.8EPSS 0.008
CVE-2021-3579
Incorrect Default Permissions vulnerability in bdservicehost.exe and Vulnerability.Scan.exe
Published 2021-10-28 · Modified
7.8EPSS 0.007
CVE-2018-6183
BitDefender Total Security 2018 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of an "insecurely created named pipe". Ensures full access to Everyone users group.
Published 2018-03-12 · Modified
7.8EPSS 0.003
CVE-2023-6154
Local privilege escalation in Bitdefender Total Security (VA-11168)
Published 2024-04-01 · Analyzed
7.8EPSS 0.002
CVE-2022-0357
Improper Quoting Path Issue in Bitdefender Total Security
Published 2023-05-24 · Modified
7.8EPSS 0.002
CVE-2020-15732
Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security versions prior to 25.0.7.29. Bitdefender Antivirus Plus versions prior to 25.0.7.29.
Published 2021-06-22 · Modified
7.5EPSS 0.005
CVE-2017-6186
Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Bitdefender process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.
Published 2017-03-21 · Modified
7.2EPSS 0.008
CVE-2019-14242
An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with administrator privileges can create a malicious DLL file in %SystemRoot%\System32\ that will be executed with local user privileges.
Published 2019-07-30 · Modified
7.2EPSS 0.006
CVE-2017-10950
This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within processing of the 0x8000E038 IOCTL in the bdfwfpf driver. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker could leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4776.
Published 2017-08-29 · Modified
7.0EPSS 0.003
CVE-2026-6851
Improper link resolution before file access in Bitdefender Total Security via Link Following (VA-13681)
Published 2026-07-14 · Analyzed
7.0EPSS 0.001
CVE-2021-4198
messaging_ipc.dll NULL Pointer Dereference in multiple Bitdefender products (VA-10016)
Published 2022-03-07 · Modified
6.1EPSS 0.006