Oracle Java Web Start Command Argument Injection Remote Code Execution
| TSL ID | TSL20120214-01 |
| CVE ID(s) | CVE-2012-0500 |
| Severity | High |
| Description | A remote code execution vulnerability exists in Oracle Java Web Start. The vulnerability is due to improper parsing of JNLP XML documents. By maliciously crafting XML an attacker can inject unexpected parameters to the java process to achieve remote code execution. A remote, unauthenticated attacker can exploit this vulnerability by enticing a target user to open a crafted Java Web Start application. Successful exploitation can lead to execution of arbitrary code with the security privileges of the target user. Oracle has released an advisory and patches regarding this vulnerability: http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html |
| Affected Products |
|
| CVSS Score |
Base 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P):
|
| Identifiers | |
| References |
http://dev.metasploit.com/redmine/projects/framework/repository/revisions/e262d7a7ffc9331135300cf2ff1e678a7312ed58/entry/modules/exploits/windows/browser/java_ws_vmargs.rb http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html |
| Related Threats |