8.8
CVSSv3

CVE-2020-8102

Published: 22/06/2020 Updated: 26/06/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web page to run remote commands inside the Safepay Utility process. This issue affects Bitdefender Total Security 2020 versions before 24.0.20.116.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bitdefender total security 2020

Recent Articles

Three words you do not want to hear regarding a 'secure browser' called SafePay... Remote. Code. Execution
The Register • Shaun Nichols in San Francisco • 24 Jun 2020

How Bitdefender's security software was caught napping by ad-block bod

Folks running Bitdefender's Total Security 2020 package should check they have the latest version installed following the disclosure of a remote code execution bug. Wladimir Palant, cofounder of Adblock-Plus-maker Eyeo, tipped off Bitdefender about the flaw, CVE-2020-8102, after discovering what he called "seemingly small weaknesses" that could be exploited by a hostile website to take control of a computer running Bitdefender's antivirus package. The bug, privately reported in April, was patche...

Three words you do not want to hear regarding a 'secure browser' called SafePay... Remote. Code. Execution
The Register • Shaun Nichols in San Francisco • 24 Jun 2020

How Bitdefender's security software was caught napping by ad-block bod

Folks running Bitdefender's Total Security 2020 package should check they have the latest version installed following the disclosure of a remote code execution bug. Wladimir Palant, cofounder of Adblock-Plus-maker Eyeo, tipped off Bitdefender about the flaw, CVE-2020-8102, after discovering what he called "seemingly small weaknesses" that could be exploited by a hostile website to take control of a computer running Bitdefender's antivirus package. The bug, privately reported in April, was patche...