CVE-2021-4198
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
07/03/2022
Last modified:
11/03/2022
Description
A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools, VPN Standalone allows an attacker to arbitrarily crash product processes and generate crashdump files. This issue affects: Bitdefender Total Security versions prior to 26.0.3.29. Bitdefender Internet Security versions prior to 26.0.3.29. Bitdefender Antivirus Plus versions prior to 26.0.3.29. Bitdefender Endpoint Security Tools versions prior to 7.2.2.92. Bitdefender VPN Standalone versions prior to 25.5.0.48.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
3.60
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:bitdefender:antivirus_plus:*:*:*:*:*:*:*:* | 26.0.3.29 (excluding) | |
cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:*:*:* | 7.2.2.92 (excluding) | |
cpe:2.3:a:bitdefender:internet_security:*:*:*:*:*:*:*:* | 26.0.3.29 (excluding) | |
cpe:2.3:a:bitdefender:total_security:*:*:*:*:*:*:*:* | 26.0.3.29 (excluding) | |
cpe:2.3:a:bitdefender:vpn_standalone:*:*:*:*:*:*:*:* | 25.5.0.48 (excluding) |
To consult the complete list of CPE names with products and versions, see this page