|
Microsoft Java Virtual Machine CODEBASE Parameter File Disclosure Vulnerability
A vulnerability has been found in the Microsoft JVM that may allow an attacker to misrepresent the location of a malicious Java applet. Through the use of an APPLET HTML tag, an attacker can specify a false value for the 'CODEBASE' parameter. An attacker can exploit this vulnerability to load a malicious applet from a remote site and trick the Virtual Machine into thinking that it was executed from a trusted location, such as the vulnerable system's hard drive. This will allow an attacker to obtain access to potentially sensitive files on a vulnerable system or network shares the user has access to. This vulnerability was originally described in BID 6365. It is now being assigned its own BugTraq ID. |
|
|
Privacy Statement |