Bitdefender Antivirus Free versions prior to 1.0.17.178 improperly handle symbolic links when restoring quarantined files. An unprivileged user can exploit this by substituting a quarantined file with a symlink, causing the restoration process to write the file to an arbitrary privileged location.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a local privilege escalation exploit for BitDefender Antivirus Free, targeting CVE-2020-8103. The exploit is implemented in C++ and is based on symbolic link manipulation techniques, leveraging code from Google's symboliclink-testing-tools. The main exploit logic resides in 'src/BitDefender Free/Exploit/Exploit.cpp'. The exploit works by creating a test file (EICAR) in a public folder, waiting for the AV to quarantine and then restore the file, and then replacing the quarantined file with a symlink to an arbitrary target file. When the user restores the file from quarantine, the AV follows the symlink and overwrites the target file with attacker-controlled content. This can be used to overwrite sensitive files and escalate privileges. The codebase is structured as a Visual Studio solution with two main projects: 'CommonUtils' (providing utilities for symlink, hardlink, and reparse point manipulation) and 'Exploit' (containing the exploit logic). The exploit requires user interaction to set up the AV exception and to trigger the restore operation. The attack vector is local, requiring access to the target system. The exploit does not use any network endpoints, but manipulates file system and registry objects. The main fingerprintable endpoints are the file paths used in the attack, particularly in the public user folders and the arbitrary file specified by the attacker.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.