CVE-2023-6154 is a local privilege-escalation vulnerability affecting Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, and Bitdefender Antivirus Free version 27.0.25.114. The issue stems from a configuration-setting weakness in the trusted front-end process seccenter.exe that can be abused through COM hijacking to load attacker-controlled code into the process, combined with insufficient restriction on privileged back-end functionality exposed through Bitdefender’s inter-process communication mechanisms. Analysis of the front-end and the loaded module safeelevatedrun.dll identified registry-operation interfaces, including a registry client used by seccenter.exe to request privileged registry writes from a high-privileged service. A low-privileged attacker can abuse this path to submit crafted registry operations targeting HKEY_LOCAL_MACHINE without adequate path restrictions. In demonstrated exploitation, the attacker changes the ImagePath configuration of a Windows service that runs as SYSTEM and can be started by a low-privileged user, then starts that service to execute attacker-controlled code as SYSTEM.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local privilege escalation vulnerability in Bitdefender Total Security that can be exploited via COM hijacking and abuse of a custom named-pipe/IPC-backed registry operation interface to gain SYSTEM privileges.
A Bitdefender Total Security privilege escalation vulnerability mentioned as the subject of a future installment in the series.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.