Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-5317

20
FAUCET Score

CVE-2025-5317 describes an improper access restriction vulnerability in Bitdefender Endpoint Security Tools for Mac (BEST) versions prior to 7.20.52.200087. This flaw allows a local attacker with administrative (sudo) privileges to bypass the configured uninstall password protection. By manually deleting specific application and library directories, an unauthorized user can effectively remove the security software without authentication. The vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and requiring local access with low privileges. The potential impact is primarily on integrity (I:H), as it allows for the unauthorized removal of the endpoint security solution, leaving the system unprotected. There is no direct impact on confidentiality or availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or concern at this time.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.20.52.200087CPE matchmatch criteria
cpe:2.3:a:bitdefender:endpoint_security:*:*:*:*:*:macos:*:*

CVSS Data

CVSS version used by this source: 4.0

6.8MEDIUM

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.10%
Probability of exploitation in next 30 days
EPSS Percentile
1.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0010 is in the 7th percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (5)

elasticvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
libvipsvendor investigatingvia llm_extracted
power_bivendor investigatingvia llm_extracted
View patch

Vendor Advisories (5)

power_billm-power_bi-e2fd6fd878ee7f30

Improper access restriction to critical folder in Bitdefender Endpoint Security Tools for Mac

Nov 11, 2025
libvipsllm-libvips-8296c1b38d3af919

Improper access restriction to critical folder in Bitdefender Endpoint Security Tools for Mac

Nov 11, 2025
hyperledgerllm-hyperledger-8040a6fda4397de5

Improper access restriction to critical folder in Bitdefender Endpoint Security Tools for Mac

Nov 11, 2025
jenkinsllm-jenkins-c644f81cf142c5ec

Improper access restriction to critical folder in Bitdefender Endpoint Security Tools for Mac

Nov 11, 2025
elasticllm-elastic-968724168e731568

Improper access restriction to critical folder in Bitdefender Endpoint Security Tools for Mac

Nov 11, 2025

References

bitdefender.com / support/security-advisories/improper-access-restriction-to-critical-folder-in-bitdefender-endpoint-security-tools-for-mac
Vendor Advisory