Microsoft Java Virtual Machine...

- AV AC AU C I A
发布: 2002-12-12
修订: 2025-04-13

Several vulnerabilities have been reported for Microsoft Java Virtual Machine. The first vulnerability may allow a malicious Java applet to access COM objects. A malicious Java applet may be able to access COM objects that allow control of the system. By exploiting this vulnerability an attacker would be able to take complete control over a compromised machine. The second vulnerability may allow an attacker to misrepresent the location of a malicious Java applet. Through the use of an APPLET HTML tag, an attacker can specify a false value for the 'CODEBASE' parameter. An attacker can exploit this vulnerability to load a malicious applet from a remote site and trick the Virtual Machine into thinking that it was executed from a trusted location. This will allow an attacker to obtain access to potentially sensitive files on a vulnerable system. The third vulnerability may allow an attacker to construct a malicious URL that would load a Java applet from an attacker's site but...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息