
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-7073 is a local privilege escalation (LPE) vulnerability affecting multiple Bitdefender consumer and enterprise security products on Windows. It allows low-privileged local attackers to escalate privileges to an elevated user context through a chain of improper symbolic link validation, file copy abuse, and DLL injection. Affected products include Bitdefender Total Security, Internet Security, Antivirus Plus (versions prior to 27.0.47.241 or 27.10.45.497), Antivirus Free (prior to 30.0.25.77), and Endpoint Security Tools (prior to 7.9.20.515). The vulnerability was published on December 10, 2025, with a patch advisory released by Bitdefender. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.8 (High) (Bitdefender Advisory).
The root cause is classified as CWE-59 (Improper Link Resolution Before File Access / 'Link Following'). The Bitdefender service process bdservicehost.exe deletes files from the user-writable directory C:\ProgramData\Atc\Feedback without validating whether the target path resolves through a symbolic link, enabling an attacker to redirect the deletion to arbitrary files. This arbitrary file deletion primitive is then chained with a file copy operation triggered during network events, and a filter driver bypass achieved via DLL injection, ultimately enabling arbitrary file copy and code execution as an elevated user. The attack requires low privileges and no user interaction, but does require local access to the target system (Bitdefender Advisory, Feedly).
Successful exploitation grants a low-privileged local attacker full elevated code execution on the affected Windows system, resulting in high confidentiality, integrity, and availability impact. An attacker can delete arbitrary files, copy arbitrary files to privileged locations, and execute code as an elevated user, effectively achieving local privilege escalation to SYSTEM or administrator-level access. This could enable persistence, credential theft, disabling of security controls, or serve as a stepping stone for lateral movement within a network (Bitdefender Advisory, Feedly).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.031%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Exploitation requires local access and low privileges, limiting the attack surface compared to remote vulnerabilities.
C:\ProgramData\Atc\Feedback, create a symbolic link (junction or symlink) pointing from a file that bdservicehost.exe is expected to delete to an arbitrary privileged file on the system (e.g., a critical system DLL or configuration file).bdservicehost.exe to perform its cleanup/deletion routine in the Feedback directory. Due to the lack of symlink validation, the service follows the link and deletes the attacker-chosen target file.C:\ProgramData\Atc\Feedback; unauthorized DLLs appearing in Bitdefender installation directories or system directories; missing or replaced system files that were previously intact.bdservicehost.exe (e.g., cmd.exe, powershell.exe, rundll32.exe); unexpected DLL loads by bdservicehost.exe visible in process monitoring tools.C:\ProgramData\Atc\Feedback correlating with symlink presence; DLL load events from non-standard paths in Bitdefender service logs.bdservicehost.exe to external IPs not associated with Bitdefender update infrastructure (Bitdefender Advisory).Bitdefender has released patched versions addressing this vulnerability. Users should update to the following versions or later: Total Security and Internet Security and Antivirus Plus ≥ 27.10.45.497 (or ≥ 27.0.47.241 for the other branch); Antivirus Free ≥ 30.0.25.77; Endpoint Security Tools ≥ 7.9.20.515. Bitdefender products typically update automatically, but administrators should verify that managed endpoints have received the update. As interim mitigations, restrict local user privileges, monitor and control access to C:\ProgramData\Atc\Feedback, and implement application whitelisting to prevent unauthorized DLL loading (Bitdefender Advisory).
Heise Online covered the vulnerability in an English-language news article highlighting the privilege escalation risk in Bitdefender antivirus products (Heise). The ENISA European Vulnerability Database (EUVD) catalogued the issue as EUVD-2025-202416. General community reaction has been limited, consistent with the absence of a public PoC or active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."