CVE-2013-0422 Java Applet JMX RCE Metasploit Demo

Опубликовано: 31 Октябрь 2024
на канале: Eric Romang (wow)
7,077
8

Blog : http://eromang.zataz.com
Twitter :   / eromang  

Timeline :

Vulnerability discovered exploited in the wild by kafeine the 2013-01-10
Metasploit PoC provided the 2013-01-10

PoC provided by:

Unknown
egypt
sinn3r
juan vazquez

Reference(s) :

CVE-2013-0422
OSVDB-89059
0 day 1.7u10 spotted in the Wild - Disable Java Plugin NOW !

Affected versions :

Oracle Java SE 7 Update 10 and bellow

Tested on Windows 8 Pro with:

Internet Explorer 10
Oracle Java SE 7 Update 10

Description :

This module abuses the JMX classes from a Java Applet to run arbitrary Java code outside of the sandbox as exploited in the wild in January of 2013. The vulnerability affects Java version 7u10 and earlier.

More on http://eromang.zataz.com/2013/01/10/j...