CVE-2025-7073
Bitdefender Internet Security vulnerability analysis and mitigation

Overview

CVE-2025-7073 is a local privilege escalation (LPE) vulnerability affecting multiple Bitdefender consumer and enterprise security products on Windows. It allows low-privileged local attackers to escalate privileges to an elevated user context through a chain of improper symbolic link validation, file copy abuse, and DLL injection. Affected products include Bitdefender Total Security, Internet Security, Antivirus Plus (versions prior to 27.0.47.241 or 27.10.45.497), Antivirus Free (prior to 30.0.25.77), and Endpoint Security Tools (prior to 7.9.20.515). The vulnerability was published on December 10, 2025, with a patch advisory released by Bitdefender. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.8 (High) (Bitdefender Advisory).

Technical details

The root cause is classified as CWE-59 (Improper Link Resolution Before File Access / 'Link Following'). The Bitdefender service process bdservicehost.exe deletes files from the user-writable directory C:\ProgramData\Atc\Feedback without validating whether the target path resolves through a symbolic link, enabling an attacker to redirect the deletion to arbitrary files. This arbitrary file deletion primitive is then chained with a file copy operation triggered during network events, and a filter driver bypass achieved via DLL injection, ultimately enabling arbitrary file copy and code execution as an elevated user. The attack requires low privileges and no user interaction, but does require local access to the target system (Bitdefender Advisory, Feedly).

Impact

Successful exploitation grants a low-privileged local attacker full elevated code execution on the affected Windows system, resulting in high confidentiality, integrity, and availability impact. An attacker can delete arbitrary files, copy arbitrary files to privileged locations, and execute code as an elevated user, effectively achieving local privilege escalation to SYSTEM or administrator-level access. This could enable persistence, credential theft, disabling of security controls, or serve as a stepping stone for lateral movement within a network (Bitdefender Advisory, Feedly).

Exploitability

As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.031%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Exploitation requires local access and low privileges, limiting the attack surface compared to remote vulnerabilities.

Exploitation steps

  1. Gain local access: Obtain a low-privileged local user account on a Windows system running a vulnerable Bitdefender product (e.g., Total Security prior to 27.0.47.241).
  2. Create a symbolic link: In the user-writable directory C:\ProgramData\Atc\Feedback, create a symbolic link (junction or symlink) pointing from a file that bdservicehost.exe is expected to delete to an arbitrary privileged file on the system (e.g., a critical system DLL or configuration file).
  3. Trigger arbitrary file deletion: Wait for or trigger the condition that causes bdservicehost.exe to perform its cleanup/deletion routine in the Feedback directory. Due to the lack of symlink validation, the service follows the link and deletes the attacker-chosen target file.
  4. Abuse file copy during network events: Trigger a network event that causes the Bitdefender service to perform a file copy operation. By controlling the source or destination through the previously established primitives, copy a malicious payload (e.g., a crafted DLL) to a privileged location.
  5. Bypass filter driver via DLL injection: Inject a malicious DLL into the Bitdefender service process or a process it loads, bypassing the filter driver's protections.
  6. Achieve elevated code execution: The injected code executes in the context of the elevated Bitdefender service, granting the attacker SYSTEM or administrator-level privileges (Bitdefender Advisory, Feedly).

Indicators of compromise

  • File System: Unexpected symbolic links or junctions created in C:\ProgramData\Atc\Feedback; unauthorized DLLs appearing in Bitdefender installation directories or system directories; missing or replaced system files that were previously intact.
  • Process: Unusual child processes spawned by bdservicehost.exe (e.g., cmd.exe, powershell.exe, rundll32.exe); unexpected DLL loads by bdservicehost.exe visible in process monitoring tools.
  • Logs: Windows Security Event Log entries showing privilege escalation (Event ID 4672 – Special privileges assigned to new logon) for unexpected accounts; file deletion events in C:\ProgramData\Atc\Feedback correlating with symlink presence; DLL load events from non-standard paths in Bitdefender service logs.
  • Network: Unexpected outbound connections from bdservicehost.exe to external IPs not associated with Bitdefender update infrastructure (Bitdefender Advisory).

Mitigation and workarounds

Bitdefender has released patched versions addressing this vulnerability. Users should update to the following versions or later: Total Security and Internet Security and Antivirus Plus ≥ 27.10.45.497 (or ≥ 27.0.47.241 for the other branch); Antivirus Free ≥ 30.0.25.77; Endpoint Security Tools ≥ 7.9.20.515. Bitdefender products typically update automatically, but administrators should verify that managed endpoints have received the update. As interim mitigations, restrict local user privileges, monitor and control access to C:\ProgramData\Atc\Feedback, and implement application whitelisting to prevent unauthorized DLL loading (Bitdefender Advisory).

Community reactions

Heise Online covered the vulnerability in an English-language news article highlighting the privilege escalation risk in Bitdefender antivirus products (Heise). The ENISA European Vulnerability Database (EUVD) catalogued the issue as EUVD-2025-202416. General community reaction has been limited, consistent with the absence of a public PoC or active exploitation.

Additional resources


SourceThis report was generated using AI

Related Bitdefender Internet Security vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-7073HIGH8.8
  • Bitdefender Internet Security logoBitdefender Internet Security
  • cpe:2.3:a:bitdefender:endpoint_security_tools
NoYesDec 10, 2025
CVE-2023-6154HIGH7.8
  • Bitdefender Internet Security logoBitdefender Internet Security
  • cpe:2.3:a:bitdefender:internet_security
NoYesApr 01, 2024
CVE-2022-0357HIGH7.8
  • Bitdefender Internet Security logoBitdefender Internet Security
  • cpe:2.3:a:bitdefender:internet_security
NoYesMay 24, 2023
CVE-2021-4199HIGH7.8
  • Bitdefender Internet Security logoBitdefender Internet Security
  • cpe:2.3:a:bitdefender:total_security
NoYesMar 07, 2022
CVE-2026-6851HIGH7
  • Bitdefender Internet Security logoBitdefender Internet Security
  • cpe:2.3:a:bitdefender:total_security
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management