mspaling/zemana-exclusions-poc

mspaling/zemana-exclusions-poc

Releases0
Proof of concept code for Zemana whitelist hijack

CVE History

CVEPublishedCVSS v3CVSS v2
5 MEDIUM

A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisting feature (MyRules2.ini under %LOCALAPPDATA%\Zemana\ZALSDK) to permit execution of unauthorized applications (such as ones that record keystrokes).