CVE-2025-7073
Severity CVSS v4.0:
HIGH
Type:
CWE-59
Link Following
Publication date:
10/12/2025
Last modified:
12/01/2026
Description
A local privilege escalation vulnerability in Bitdefender Total Security 27.0.46.231 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user.
Impact
Base Score 4.0
8.80
Severity 4.0
HIGH
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:bitdefender:antivirus:*:*:*:*:free:*:*:* | 30.0.25.77 (excluding) | |
| cpe:2.3:a:bitdefender:antivirus_plus:*:*:*:*:*:*:*:* | 27.10.45.497 (excluding) | |
| cpe:2.3:a:bitdefender:endpoint_security_tools:*:*:*:*:*:windows:*:* | 7.9.20.515 (excluding) | |
| cpe:2.3:a:bitdefender:internet_security:*:*:*:*:*:*:*:* | 27.10.45.497 (excluding) | |
| cpe:2.3:a:bitdefender:total_security:*:*:*:*:*:*:*:* | 27.10.45.497 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



