CVE-2007-6189

BitDefender Online Anti-Virus Scanner 8.0 - RCE

Title source: llm

Description

A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper memory allocation and a heap-based buffer overflow.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nphinity · htmlremotewindows
https://www.exploit-db.com/exploits/4663

Scores

EPSS 0.2323
EPSS Percentile 96.0%

Details

CWE
CWE-119
Status published
Products (1)
bitdefender/online_anti-virus_scanner 8.0
Published Nov 30, 2007
Tracked Since Feb 18, 2026