Remote code execution in Bitdefender SafePay



Published: 2019-01-31
Risk High
Patch available YES
Number of vulnerabilities 3
CVE-ID CVE-2019-6738
CVE-2019-6737
CVE-2019-6736
CWE-ID CWE-20
CWE-77
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
SafePay
Client/Desktop applications / Web browsers

Vendor Bitdefender

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) Input validation error

EUVDB-ID: #VU17329

Risk: High

CVSSv3.1: 8.3 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-6738

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists within the processing of TIScript due to insufficient validation of user-supplied input. A remote attacker can trick the victim into visiting a malicious page or opening a malicious file and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

Mitigation

Update to version 23.0.11.44.

Vulnerable software versions

SafePay: before 23.0.11.44

External links

http://www.zerodayinitiative.com/advisories/ZDI-19-159/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to visit a specially crafted website.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Input validation error

EUVDB-ID: #VU17330

Risk: High

CVSSv3.1: 8.3 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-6737

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists within handling of the openFile method due to insufficient validation of user-supplied input. A remote attacker can trick the victim into visiting a malicious page or opening a malicious file and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

Mitigation

Update to version 23.0.11.44.

Vulnerable software versions

SafePay: before 23.0.11.44

External links

http://www.zerodayinitiative.com/advisories/ZDI-19-158/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to visit a specially crafted website.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Command injection

EUVDB-ID: #VU17331

Risk: High

CVSSv3.1: 8.3 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-6736

CWE-ID: CWE-77 - Command injection

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists within the processing of tiscript due to insufficient validation of user-supplied input when processing the System.Exec method. A remote attacker can trick the victim into visiting a malicious page or opening a malicious file, inject arbitrary commands and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise

Mitigation

Update to version 23.0.11.44.

Vulnerable software versions

SafePay: before 23.0.11.44

External links

http://www.zerodayinitiative.com/advisories/ZDI-19-157/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to visit a specially crafted website.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###