Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-2224


Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1


Published

2024-04-09T13:15:33.357

Last Modified

2025-02-07T18:53:18.953

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application bitdefender endpoint_security 7.0.5.200089 Yes
Application bitdefender endpoint_security 7.9.9.380 Yes
Application bitdefender gravityzone_control_center 6.36.1 Yes

References