← Back

CVE-2024-2224

nvd nist
Published: Apr 9, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1

Affected (3)

2 products
Endpoint Security
Gravityzone Control Center
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Bitdefender
Version 7.0.5.200089
Version 7.9.9.380
Version 6.36.1

Timeline

No history available yet.