|
Brought to you by:
Suppliers of:
|
|
|
| |
BitDefender provides security solutions to satisfy the protection requirements of today's computing environment, delivering effective threat management for over 41 million home and corporate users in more than 100 countries.
The heuristics of Bitdefender can be bypassed by a special formatted PDF "container", this leads to the bypass of malicious PDF files, old or new. This is not a bypass that relies on archive structures but relies on evading certain code paths in the AV engine "through various means". Interestingly this opens the possibility to evade at scan time and run-time. |
| |
Credit:
The information has been provided by Thierry Zoller.
The original article can be found at: http://blog.zoller.lu/2009/04/advisory-bitdefender-generic-evasion.html
|
| |
Vulnerable Systems:
* Bitdefender Antivirus 2009
* Bitdefender Internet Security 2009
* Bitdefender Total Security 2009
* Bitdefender Small Office Security
* Bitdefender for Fileservers
* Bitdefender for Samba
* Bitdefender for Sharepoint
* Bitdefender Security for Exchange
* Bitdefender Security for Mailservers
* Bitdefender for ISA Servers
* Bitdefender Client security
Patch Availability:
Bitdefender Signature update after 13.05.2009
Disclosure Timeline:
08/05/2009 : Send proof of concept,
13/05/2009 : Patch was deployed.
|
|
|
|
|