Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow, aka the "cevakrnl.xmd vulnerability."
2006-12-18T11:28:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | softwin | bitdefender | isa_server | Yes |
Application | softwin | bitdefender | ms_exchange_5.5 | Yes |
Application | softwin | bitdefender | ms_exchange_2000 | Yes |
Application | softwin | bitdefender | ms_exchange_2003 | Yes |
Application | softwin | bitdefender_antivirus | * | Yes |
Application | softwin | bitdefender_antivirus | plus | Yes |
Application | softwin | bitdefender_internet_security | * | Yes |
Application | softwin | bitdefender_mail_protection | enterprises | Yes |
Application | softwin | bitdefender_online_scanner | * | Yes |