Skip to main content
CVE Vulnerability Database

CVE-2025-7073: Bitdefender Antivirus Privilege Escalation

CVE-2025-7073 is a local privilege escalation vulnerability in Bitdefender Total Security that allows low-privileged attackers to gain elevated access. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2025-7073 Overview

CVE-2025-7073 is a local privilege escalation vulnerability affecting Bitdefender Total Security and related consumer and endpoint products prior to version 27.0.47.241. The flaw exists in bdservicehost.exe, which deletes files from the user-writable directory C:\ProgramData\Atc\Feedback without validating symbolic links. A low-privileged attacker can abuse this behavior to achieve arbitrary file deletion. When chained with a file copy triggered by network events and a filter driver bypass via DLL injection, the attacker can perform arbitrary file copies and execute code as an elevated user. The weakness is classified under CWE-59: Improper Link Resolution Before File Access.

Critical Impact

A local attacker with standard user privileges can escalate to elevated privileges and execute arbitrary code on affected Bitdefender installations.

Affected Products

  • Bitdefender Antivirus (Free) prior to 27.0.47.241
  • Bitdefender Antivirus Plus, Internet Security, and Total Security prior to 27.0.47.241
  • Bitdefender Endpoint Security Tools for Windows prior to 27.0.47.241

Discovery Timeline

  • 2025-12-10 - CVE-2025-7073 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-7073

Vulnerability Analysis

The vulnerability originates in the Bitdefender service bdservicehost.exe, which runs with elevated privileges. The service deletes files from C:\ProgramData\Atc\Feedback, a directory writable by low-privileged users. Because the service does not validate whether entries in this directory are symbolic links, junctions, or hard links, an attacker can redirect the delete operation to arbitrary files on the file system.

Exploitation requires chaining three primitives. First, the attacker plants a symbolic link inside the feedback directory to convert the trusted deletion into an arbitrary file delete. Second, a file copy operation triggered by network events is redirected to a target path controlled by the attacker. Third, a filter driver bypass via DLL injection allows the attacker to place a malicious payload that the elevated service loads. The end result is code execution in an elevated security context from a low-privileged starting position.

Root Cause

The root cause is the absence of link resolution checks before file operations in a security-sensitive path [CWE-59]. bdservicehost.exe implicitly trusts filesystem entries in a directory that any local user can modify. This design pattern violates the principle of validating the final target of a filesystem operation before performing privileged actions.

Attack Vector

The attack vector is local and requires an authenticated low-privileged user on the target host. Attack complexity is high because the attacker must win the timing window between file staging and the service's delete or copy operation, and must combine the primitive with a DLL injection technique to bypass the Bitdefender filter driver. No user interaction is required beyond the attacker's own actions. Refer to the Bitdefender Security Advisory for vendor-specific technical detail.

Detection Methods for CVE-2025-7073

Indicators of Compromise

  • Creation of symbolic links, junctions, or reparse points inside C:\ProgramData\Atc\Feedback by non-SYSTEM accounts.
  • Unexpected deletion of files outside C:\ProgramData\Atc\Feedback attributed to bdservicehost.exe.
  • DLL loads by Bitdefender processes from user-writable directories that are not part of the official installation.

Detection Strategies

  • Monitor filesystem minifilter events for reparse point creation by unprivileged users in C:\ProgramData\Atc\ subdirectories.
  • Correlate bdservicehost.exe file operations against unexpected target paths, especially in System32, Program Files, and startup locations.
  • Alert on module loads by signed Bitdefender binaries where the module path resides in a world-writable directory.

Monitoring Recommendations

  • Audit installed Bitdefender version data across the fleet and confirm builds are at or above 27.0.47.241.
  • Track child processes and impersonation events originating from bdservicehost.exe to identify anomalous privilege usage.
  • Retain endpoint telemetry covering symbolic link creation and DLL load events for retrospective hunting.

How to Mitigate CVE-2025-7073

Immediate Actions Required

  • Upgrade all affected Bitdefender products to version 27.0.47.241 or later using the built-in auto-update mechanism.
  • Verify Bitdefender Endpoint Security Tools deployments on managed Windows endpoints reflect the patched build in the central console.
  • Restrict interactive logon on servers running Bitdefender to trusted administrators to reduce local exploitation opportunities.

Patch Information

Bitdefender addressed the issue in build 27.0.47.241 for consumer products and the corresponding release for Endpoint Security Tools. The fix introduces symbolic link validation before file deletion and copy operations performed by bdservicehost.exe. See the Bitdefender Security Advisory ATC-VA-12590 for full remediation guidance.

Workarounds

  • No official vendor workaround exists; patching is the supported remediation.
  • As a compensating control, restrict write permissions on C:\ProgramData\Atc\Feedback where the product configuration allows, and monitor the directory for reparse point creation.
  • Enforce application control policies that prevent DLL loads from user-writable directories by signed security-product binaries.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.