CVE-2019-14242 is a local code injection vulnerability affecting several Bitdefender products for Windows, including Endpoint Security Tool, Antivirus Plus, Internet Security, and Total Security, in versions prior to their respective patches. This medium-severity vulnerability (CVSS 6.7) allows a local attacker with administrator privileges to execute arbitrary code with local user privileges by placing a malicious DLL in the System32 directory. While the potential impact is high for confidentiality, integrity, and availability, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 23.0.24.120CPE matchmatch criteria | cpe:2.3:a:bitdefender:antivirus_plus:*:*:*:*:*:*:*:* | ||
< 6.6.8.115CPE matchmatch criteria | cpe:2.3:a:bitdefender:endpoint_security_tool:*:*:*:*:*:*:*:* | ||
< 23.0.24.120CPE matchmatch criteria | cpe:2.3:a:bitdefender:internet_security:*:*:*:*:*:*:*:* | ||
< 23.0.24.120CPE matchmatch criteria | cpe:2.3:a:bitdefender:total_security:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.