Vulnerability fixed in BitDefender Update Server An issue has been identified in a component of BitDefender update server (CVE-2008-0396). Successful exploit of the vulnerability may allow read access to files outside of the application's root directory with named privileges.
This issue only affects customers hosting their own internal BitDefender Update server. Customers updating directly from BitDefender are not affected. Additionally, this issue does not affect any Consumer product such as BitDefender Total Security, BitDefender Internet Security or BitDefender Antivirus.
The risk level of this vulnerability is low and at this moment no known malicious exploit has been observed in the wild.
Starting with version 2.4 BitDefender Security for Windows Servers checks the integrity of the updates it downloads from the update server. Thus, when updating from a local BitDefender Update Server the update process might fail.
The present document explains how to configure BitDefender Security for Windows Servers to update from a local update server.
BitDefender Security for File Servers and DFS After installing BitDefender Security for File Servers on a server using the DFS technology it is possible that the respective server will crash with blue screen when the replication feature is active.