Description

A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user.

INFO

Published Date :

2025-12-10T09:46:40.263Z

Last Modified :

2026-03-31T11:43:59.146Z

Source :

Bitdefender
AFFECTED PRODUCTS

The following products are affected by CVE-2025-7073 vulnerability.

Vendors Products
Bitdefender
  • Antivirus
  • Antivirus Plus
  • Endpoint Security Tools
  • Internet Security
  • Total Security
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-7073.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact