# CVE-2025-7073

## Summary

- **CVE ID:** CVE-2025-7073
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-59
- **Published:** Dec 10, 2025
- **Last Modified:** Mar 31, 2026

## Description

A local privilege escalation vulnerability in Bitdefender Total Security 27.0.46.231 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user.

## Affected Products

- Bitdefender — Total Security (0)
- Bitdefender — Internet Security (0)
- Bitdefender — Antivirus Plus (0)

## References

- [CNA](https://www.bitdefender.com/support/security-advisories/local-privilege-escalation-via-arbitrary-file-operation-in-bitdefender-atc-va-12590)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._