CVE-2026-6851 is an Improper link resolution before file access ('link following') vulnerability in the File Shredder module used in Bitdefender Total Security and Internet Security on Windows. The issue allows a less-privileged local user to elevate rights by leveraging a race condition via Symbolic Links. This issue affects Total Security: before 27.0.58.315; Internet Security: before 27.0.58.315. The v [truncated]
A local privilege escalation vulnerability in Bitdefender Total Security and related products allows low-privileged attackers to elevate privileges through a multi-stage attack chain. The vulnerability stems from improper symbolic link validation in the bdservicehost.exe service, which deletes files from a user-writable directory (C:ProgramDataAtcFeedback) without adequate security checks. This arbitrary [truncated]