cve/2018/CVE-2018-8955.md
2024-05-26 14:27:05 +02:00

1.0 KiB

CVE-2018-8955

Description

The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged.

POC

Reference

Github