CVE-2013-0431 Java Applet JMX Remote Code Execution Metasploit Demo

Опубликовано: 18 Июнь 2026
на канале: Eric Romang (wow)
2,941
8

Blog : http://eromang.zataz.com
Twitter :   / eromang  
More on: http://eromang.zataz.com/2013/02/25/c...

Timeline :

Vulnerability discovered and reported to the vendor by Security Explorations the 2013-01-18
Vulnerability patched by the vendor the 2013-02-01
Vulnerability discovered exploited in the wild by kafeine and EKwatcher the 2013-02-18
Metasploit PoC provided the 2013-02-25

PoC provided by:

Unknown
Adam Gowdiak
SecurityObscurity
juan vazquez

Reference(s) :

OSVDB-89613
BID-57726
CVE-2013-0431
Malware don't need Coffee
Security Explorations
Security Obscurity

Affected versions :

Java SE 7U11 and previous

Tested on Windows 7 Integral SP1 with:

Java SE 7U11

Description :

This module abuses the JMX classes from a Java Applet to run arbitrary Java code outside of the sandbox as exploited in the wild in February of 2013. Additionally, this module bypasses default security settings introduced in Java 7 Update 10 to run unsigned applet without displaying any warning to the user.