6.8
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Description
An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass the configured uninstall password protection. An unauthorized user with sudo privileges can manually remove the application directory (/Applications/Endpoint Security for Mac.app/) and the related directories within /Library/Bitdefender/AVP without needing the uninstall password.
Basic Information
ID
CVE-2025-5317
Source
Bitdefender
Published
Nov 11, 2025 at 08:02
Modified
Nov 11, 2025 at 08:10
Affected Product
Vendor
Bitdefender
Product
Endpoint Security Tools for Mac
Affected Versions
Bitdefender Endpoint Security Tools for Mac 0