CVE-2024-2223: Bitdefender Endpoint Security

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component:  Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for  Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1

Affected products

  • Bitdefender Endpoint Security: version 7.0.5.200089 only; version 7.9.9.380 only
  • Bitdefender Gravityzone Control Center: version 6.36.1 only

Published 2024-04-09. Last modified 2026-06-17.