CVE-2025-7073 - Local Privilege Escalation via Arbitrary File Operation in Bitdefender Total Secu...

CVE-2025-7073 - Local Privilege Escalation via Arbitrary File Operation in Bitdefender Total Secu...

CVE ID : CVE-2025-7073 Published : Dec. 10, 2025, 10:16 a.m. | 30 minutes ago Description : A local privilege escalation vulnerability in Bitdefender Total Security 27.0.46.231 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
LOW
Published
Dec. 10, 2025
Attack Vector: local
Impact: privilege escalation

Source: Telegram CVE Monitor