A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injection) without being blocked by AppleMobileFileIntegrity (AMFI). This issue is caused by the absence of Hardened Runtime or Library Validation signing. This issue affects Bitdefender Virus Scanner versions before 3.18.
History

Tue, 11 Feb 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Bitdefender
Bitdefender virus Scanner
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:bitdefender:virus_scanner:*:*:*:*:*:macos:*:*
Vendors & Products Bitdefender
Bitdefender virus Scanner
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 14 Jan 2025 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jan 2025 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injection) without being blocked by AppleMobileFileIntegrity (AMFI). This issue is caused by the absence of Hardened Runtime or Library Validation signing. This issue affects Bitdefender Virus Scanner versions before 3.18.
Title Insufficient Hardened Runtime or Library Validation signing in Bitdefender Virus Scanner for macOS
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Bitdefender

Published:

Updated: 2025-01-14T00:17:56.801Z

Reserved: 2024-11-12T07:36:28.444Z

Link: CVE-2024-11128

cve-icon Vulnrichment

Updated: 2025-01-14T00:17:51.808Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-13T22:15:13.680

Modified: 2025-02-11T21:38:28.860

Link: CVE-2024-11128

cve-icon Redhat

No data.