Junglewise Threat Intelligence

CVE-2025-7073: Bitdefender Total Security local privilege escalation in ATC module

CVE-2025-7073 · Severity: high · CVSS 7.8 · Published 2025-12-10

Technologies: Bitdefender Internet Security, Bitdefender Total Security, Bitdefender Antivirus. Vendors: Bitdefender.

Executive brief

A security vulnerability in Bitdefender antivirus products could allow a user with limited access to gain full administrative control over a computer. By manipulating temporary files used by the software, an attacker can delete or replace critical system files. This could lead to a complete system takeover, data theft, or the disabling of security protections.

Technical details

A local privilege escalation vulnerability exists in the Active Threat Control (ATC) module of several Bitdefender products due to improper symbolic link validation in 'bdservicehost.exe'. The service attempts to delete files within the user-writable 'C:\ProgramData\Atc\Feedback' directory; a local attacker can use symbolic links to redirect these deletions to arbitrary system files. By chaining this arbitrary file deletion with a file copy operation triggered during network events and bypassing filter drivers via DLL injection, an attacker can achieve arbitrary file writes and code execution with SYSTEM privileges. The vulnerability is patched in Total Security/Internet Security/Antivirus Plus version 27.0.47.241, Antivirus Free version 30.0.25.77, and BEST for Windows version 7.9.20.515.

Affected products

  • Bitdefender Total Security < 27.0.47.241
  • Bitdefender Internet Security < 27.0.47.241
  • Bitdefender Antivirus Plus < 27.0.47.241
  • Bitdefender Antivirus Free < 30.0.25.77
  • Bitdefender Endpoint Security Tools for Windows < 7.9.20.515

Timeline

  • 2025-12-10: disclosed
  • 2025-12-10: advisory

References

Related threats