Cryptzone SE46 Application Whitelisting contains a flaw that is triggered during the handling of a specially crafted 16-bit COM .pif file that does not have the mz prefix or is a BAT, CMD, COM or EXE extension. This may allow a remote attacker to bypass the blacklisting restriction feature and execute arbitrary commands stored in the file.
Disclosure Timeline:
Disclosure Date :2013-01-10
Exploit Publish Date :2013-01-10