McAfee Application Control contains a flaw that is due to the program only checking files for valid headers, if a header is not valid it allows the file on to the system assuming it is not executable. With a specially crafted .SCR file, a remote attacker can bypass file restrictions and upload arbitrary files to the system.
Disclosure Timeline:
Disclosure Date :2013-01-10
Exploit Publish Date :2013-01-10