CVE-2018-8955

The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged.
Configurations

Configuration 1

cpe:2.3:a:bitdefender:gravityzone:-:*:*:*:*:*:*:*

Information

Published : 2018-10-24 10:29

Updated : 2019-01-25 08:01


NVD link : CVE-2018-8955

Mitre link : CVE-2018-8955

Products Affected
No products.
CWE
CWE-347

Improper Verification of Cryptographic Signature