Vulnerability discovered in BitDefender Online Scanner

Nov 21, 2007 08:05 GMT  ·  By

Since it's accessible via a web-browser, BitDefender Online Scanner is pretty useful when an infection managed to reach your computer and affect the data stored on your drives. But this doesn't necessarily mean the service is also 100 percent safe as a new vulnerability was reported today by Security Focus. Under the "BitDefender Online Scanner OScan. OCX ActiveX Control Heap Buffer Overflow Vulnerability" title, Security Focus informs the flaw affects only BitDefender Online Scanner 8 but at this time, there's no successful exploitation confirmed.

"BitDefender Online Scanner is prone a heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data," Security Focus wrote in the advisory.

"Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions."

BitDefender Online Scanner is surely one of the top alternatives when it comes to online computer disinfection because it uses the power of the famous BitDefender Antivirus to remove threats and malicious files from users' systems. But why would you turn to BitDefender Online Scanner when you already have a powerful downloadable security solution installed on your system?

It's simple. Imagine that there are moments when some dangerous threats manage to disable antivirus protection or even compromise its files, making your security solution somehow useless. In such a trouble, your offline antivirus can't protect your computer so the only way to remove the infections would be scanning online with one web-based technologies. Sure, you can choose between several solutions such as Kaspersky's Online Scanner or BitDefender's, both of them being pretty useful for an online product.

In case you would like to scan your computer with BitDefender Online Scanner, you can access the service using this link. Kaspersky's web-based antivirus tool is available here.