CVE-2021-4199
Last modified
CVE-2021-4199 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.3.146.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bitdefender | Antivirus Plus | < 26.0.3.29 |
| Bitdefender | Endpoint Security Tools | < 7.4.3.146 |
| Bitdefender | Internet Security | < 26.0.3.29 |
| Bitdefender | Total Security | < 26.0.3.29 |
References
- https://www.zerodayinitiative.com/advisories/ZDI-22-484/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-484/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-4199?
How severe is CVE-2021-4199?
How do I fix CVE-2021-4199?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-41984Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-41985Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-41986Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-41987In the SCEP Server of RouterOS in certain Mikrotik products,…8.1
- CVE-2021-41988Qlik NPrinting Designer through 21.14.3.0 creates a Temporar…7.8
- CVE-2021-41989Qlik QlikView through 12.60.20100.0 creates a Temporary File…7.8
- CVE-2021-41990The gmp plugin in strongSwan before 5.9.4 has a remote integ…7.5
- CVE-2021-41991The in-memory certificate cache in strongSwan before 5.9.4 h…7.5
- CVE-2021-41992A misconfiguration of RSA in PingID Windows Login prior to 2…5.6
- CVE-2021-41993A misconfiguration of RSA in PingID Android app prior to 1.1…4.8
- CVE-2021-41994A misconfiguration of RSA in PingID iOS app prior to 1.19 is…4.8
- CVE-2021-41995A misconfiguration of RSA in PingID Mac Login prior to 1.1 i…7.5
Are you affected by CVE-2021-4199?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
