CVE detail
CVE-2024-11128 — CVE-2024-11128
Published 2025-01-13 · Modified 2026-06-17 · Vendor bitdefender · Product virus_scanner · Source nvd
HIGH
severity
CVSS-derived band
0.0016
EPSS probability
exploitation probability, 30d
6.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injection) without being blocked by AppleMobileFileIntegrity (AMFI). This issue is caused by the absence of Hardened Runtime or Library Validation signing. This issue affects Bitdefender Virus Scanner versions before 3.18.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References