Description: fRoGGz has discovered a vulnerability in BitDefender Anti-Virus, which potentially can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a format string error when generating the scan report file. This can potentially be exploited to execute arbitrary code when a file or directory containing format string specifiers in its name (e.g. %.8X%.8X) is scanned.
Successful exploitation requires that the "Create report file" option is enabled.
The vulnerability has been confirmed in version 9.0, and also reported in versions 7.2 and 8. Other versions may also be affected.
Solution: Update to the fixed version via online update.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.