« Volver al listado

CVE-2023-6154

Estado: AnalizadaAlta (7.8)—

A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This issue affects Total Security: 27.0.25.114; Internet Security: 27.0.25.114; Antivirus Plus: 27.0.25.114; Antivirus Free: 27.0.25.114.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6154",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-6154",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-02T15:38:45.661553Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-requests@bitdefender.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve-requests@bitdefender.com",
      "affectedData": [
        {
          "vendor": "Bitdefender",
          "product": "Total Security",
          "versions": [
            {
              "status": "affected",
              "version": "27.0.25.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Bitdefender",
          "product": "Internet Security",
          "versions": [
            {
              "status": "affected",
              "version": "27.0.25.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Bitdefender",
          "product": "Antivirus Plus",
          "versions": [
            {
              "status": "affected",
              "version": "27.0.25.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Bitdefender",
          "product": "Antivirus Free",
          "versions": [
            {
              "status": "affected",
              "version": "27.0.25.114"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:bitdefender:total_security:27.0.25.114:*:*:*:*:*:*:*"
          ],
          "vendor": "bitdefender",
          "product": "total_security",
          "versions": [
            {
              "status": "affected",
              "version": "27.0.25.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:a:bitdefender:internet_security:27.0.25.114:*:*:*:*:*:*:*"
          ],
          "vendor": "bitdefender",
          "product": "internet_security",
          "versions": [
            {
              "status": "affected",
              "version": "27.0.25.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:a:bitdefender:antivirus_plus:27.0.25.114:*:*:*:*:*:*:*"
          ],
          "vendor": "bitdefender",
          "product": "antivirus_plus",
          "versions": [
            {
              "status": "affected",
              "version": "27.0.25.114"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:a:bitdefender:antivirus:27.0.25.114:*:*:*:*:*:*:*"
          ],
          "vendor": "bitdefender",
          "product": "antivirus",
          "versions": [
            {
              "status": "affected",
              "version": "27.0.25.114"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-04-01T11:15:52.437",
  "references": [
    {
      "url": "https://bitdefender.com/support/security-advisories/local-privilege-escalation-in-bitdefender-total-security-va-11168/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-requests@bitdefender.com"
    },
    {
      "url": "https://bitdefender.com/support/security-advisories/local-privilege-escalation-in-bitdefender-total-security-va-11168/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-requests@bitdefender.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-15"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-610"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This issue affects Total Security: 27.0.25.114; Internet Security: 27.0.25.114; Antivirus Plus: 27.0.25.114; Antivirus Free: 27.0.25.114."
    },
    {
      "lang": "es",
      "value": "Un problema de configuración en seccenter.exe tal como se usa en Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free permite a un atacante cambiar el comportamiento esperado del producto y potencialmente cargar una librería de terceros durante la ejecución. Este problema afecta a Total Security: 27.0.25.114; Seguridad de Internet: 27.0.25.114; Antivirus Plus: 27.0.25.114; Antivirus gratuito: 27.0.25.114."
    }
  ],
  "lastModified": "2026-06-17T06:50:09.743",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bitdefender:antivirus:27.0.25.114:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "074D439F-4C3C-4845-99BD-ABC7B47EE1B5"
            },
            {
              "criteria": "cpe:2.3:a:bitdefender:antivirus_plus:27.0.25.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB2FDBB0-D112-4C3A-88EB-5781603B9BF1"
            },
            {
              "criteria": "cpe:2.3:a:bitdefender:internet_security:27.0.25.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D12934F6-C291-42CC-92D0-FDDEB7BC11C0"
            },
            {
              "criteria": "cpe:2.3:a:bitdefender:total_security:27.0.25.114:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAE8BCB4-83AD-44B0-B0F7-45A43D23968B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-requests@bitdefender.com"
}