Highly critical flaw reported in the application

Jan 24, 2007 11:52 GMT  ·  By

Virtual CD was one of the innovative applications that allow you to create copies of your CDs or other discs and use them directly from your computer. There are a lot of similar software solutions, but Virtual CD was one of the first programs in its category and was very popular in the past. Although multiple users were looking for an alternative, there are a lot of clients that are still using Virtual CD as the default application of this genre in their system. The solution allows you to use up to 23 virtual drives simultaneously and with an unlimited number of virtual CDs.

Security company Secunia recently confirmed that a highly critical vulnerability was identified in this application, a flaw that can allow an attacker to control an affected computer without the approval of the owner. The security firm added that the affected versions of the program are Virtual CD 6.x, Virtual CD 7.x, Virtual CD 8.x and Virtual CD File Server 7.x.

"Secunia Research has discovered a vulnerability in two Virtual CD products, which can be exploited by malicious people to compromise a user's system. The vulnerability is confirmed in Virtual CD versions 6.0.0.7, 7.1.0.2, and 8.0.0.6 and Virtual CD File Server version 7.1.0.3. Other versions may also be affected," Secunia said.

Although Carsten Eiram, Secunia Research, recommends you to look for another application or try to resolve the issue by setting the kill-bit for the ActiveX control, I think it's more adequate to wait for an updated version of the program or even for a fix patch meant to repair the problem.

Virtual CD 8.1 was also tested by Softpedia and it is available as a free download on this link.