Serious Remote Code Execution Flaw Found In Bitdefender Total Security 2020

  •  
  •  
  •  
  • 1
  •  
  •  
  •  
    1
    Share

A serious security flaw existed in the Bitdefender Total Security 2020 software. As discovered by the researcher, this vulnerability could allow remote code execution to an attacker upon exploitation.

Bitdefender Total Security 2020 Flaw

Reportedly, a security researcher Wladimir Palant found a high-severity flaw in Bitdefender Total Security 2020 solution.

Sharing the details in a post, the researcher revealed that the flaw affected the SafePay browser component of the software. Bitdefender’s SafePay browser is a dedicated feature to ensure secure online banking.

Briefly, the researcher caught numerous small vulnerabilities that could together lead to devastating results.

As a standard, Bitdefender used to display custom error pages while inspecting HTTPS connections instead of leaving it to the browser. This, in turn, allowed websites to read security tokens from these pages, which an adversary could potentially exploit.

As stated in the post,

These security tokens cannot be used to override errors on other websites, but they can be used to start a session with the Chromium-based Safepay browser. This API was never meant to accept untrusted data, so… command line flags can be injected, which in the worst case results in arbitrary applications starting up.

Bitdefender Patched The Vulnerability

The researcher Palant, after discovering this flaw, reported the matter to Bitdefender via their bug bounty program. Bitdefender also acknowledged the flaw that received the CVE ID CVE-2020-8102, and a severity score of 8.8.

Later, Bitdefender patched the flaw in Bitdefender Total Security 2020 with the release of version 24.0.20.116.

Describing the details in an advisory, the vendors stated,

Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web page to run remote commands inside the Safepay Utility process.

Though, users don’t have to worry about this bug since the update will automatically reach their devices. However, they can always check their software manually for any updates as well.

The following two tabs change content below.

Abeerah Hashim

Abeerah has been a passionate blogger for several years with a particular interest towards science and technology. She is crazy to know everything about the latest tech developments. Knowing and writing about cybersecurity, hacking, and spying has always enchanted her. When she is not writing, what else can be a better pastime than web surfing and staying updated about the tech world! Reach out to me at: [email protected]

Abeerah Hashim

Abeerah has been a passionate blogger for several years with a particular interest towards science and technology. She is crazy to know everything about the latest tech developments. Knowing and writing about cybersecurity, hacking, and spying has always enchanted her. When she is not writing, what else can be a better pastime than web surfing and staying updated about the tech world! Reach out to me at: [email protected]

Do NOT follow this link or you will be banned from the site!