CVE-2025-5317
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-11

Last updated on: 2025-12-08

Assigner: Bitdefender

Description
An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass the configured uninstall password protection. An unauthorized user with sudo privileges can manually remove the application directory (/Applications/Endpoint Security for Mac.app/) and the related directories within /Library/Bitdefender/AVP without needing the uninstall password.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-11
Last Modified
2025-12-08
Generated
2026-05-07
AI Q&A
2025-11-11
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
bitdefender endpoint_security to 7.20.52.200087 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an improper access restriction in Bitdefender Endpoint Security Tools for Mac before version 7.20.52.200087. It allows local users with administrative (sudo) privileges to bypass the uninstall password protection by manually removing the application directory and related directories without needing the uninstall password.


How can this vulnerability impact me? :

The vulnerability allows an unauthorized user with sudo privileges to uninstall Bitdefender Endpoint Security Tools without the configured uninstall password. This could lead to the removal of security protections on the Mac system, potentially exposing the system to malware or other security threats.


How can this vulnerability be detected on my network or system? Can you suggest some commands?

You can detect this vulnerability by checking if the Bitdefender Endpoint Security Tools for Mac application directory (/Applications/Endpoint Security for Mac.app/) and related directories within /Library/Bitdefender/AVP exist and verifying if local users with administrative privileges can access or remove these directories without requiring the uninstall password. Commands such as `ls -ld /Applications/Endpoint\ Security\ for\ Mac.app/` and `ls -ld /Library/Bitdefender/AVP` can be used to check directory permissions. Additionally, attempting to remove these directories with sudo privileges without the uninstall password can confirm the vulnerability.


What immediate steps should I take to mitigate this vulnerability?

Immediate mitigation steps include restricting local user access with administrative privileges to prevent unauthorized removal of the application directories. Ensure that uninstall password protection is properly enforced and consider upgrading Bitdefender Endpoint Security Tools for Mac to version 7.20.52.200087 or later, where this vulnerability is fixed.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart