Wednesday, January 23, 2013

CVE-2012-5088 Java Applet Method Handle RCE Metasploit Demo


This module abuses the Method Handle class from a Java Applet to run arbitrary Java code outside of the sandbox. The vulnerability affects Java version 7u7 and earlier.









Timeline :

  • Vulnerability patched by Oracle in 2012 October CPU
  • Metasploit PoC provided the 2013-01-22

PoC provided by :

  • Unknown
  • juan vazquez

Reference(s) :


Affected version(s) :

  • Oracle Java version 7 Update 7 and earlier.

Tested on Windows 8 Pro with :

  • Internet Explorer 10
  • Oracle Java 7 Update 7
Demo : 


Source : eromang.zataz.com

No comments:

Post a Comment