Today, there are many security to protect a business from online threats. However, sometimes the solutions themselves can be a risk to the business. This was the case with Bitdefender antivirus, which contains a vulnerability that allows remote execution of malicious code.

The vulnerability, called CVE-2020–8102, affects the recently updated version of Bitdefender antivirus. Security researchers claim that the vulnerability in question could have a large impact, as the antivirus in which it was discovered is used by many users to protect their systems.
About vulnerability
According to researchers, the vulnerability is due to incorrect login validation in the Safepay browser, which is a highlight of Bitdefender Total Security 2020 .
It could allow an external, specially crafted website to execute remote commands within the Safepay Utility. According to researchers, this vulnerability affects Bitdefender Total Security 2020 versions 24.0.20.116.
Details about the vulnerability:
- CVE-ID: CVE-2020-8102
- CVSS score: 8.8
- Affected providers: Bitdefender
- Affected products: Bitdefender SafePay

Antivirus programs are used to protect devices and keep them safe from online dangers. However, when the same protection programs can allow hackers to exploit them, it can have particularly negative results for a business or user.
Additionally, Bitdefender is investigating this issue and has installed an automatic update that fixes this vulnerability in versions 24.0.20.116 and will also be fixed in all subsequent versions.
