CVE-2024-2224: Bitdefender Endpoint Security

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089 Bitdefender Endpoint Security for Windows version 7.9.9.380 GravityZone Control Center (On Premises) version 6.36.1

Affected products

  • Bitdefender Endpoint Security: version 7.0.5.200089 only; version 7.9.9.380 only
  • Bitdefender Gravityzone Control Center: version 6.36.1 only

Published 2024-04-09. Last modified 2026-06-17.