Web Hack List

Collected research

Fireeye -- Arbitrary reading and writing of the JVM process

The Java Zero-Day Procession Continues

A Java zero-day found exploited in the wild against Java 6u41 and 7u15. Instead of the usual sandbox-permission tricks it targets the JVM's internal data structures for arbitrary memory read and write, zeroing memory to fetch a McRAT payload. It is unreliable and often crashes the JVM; Oracle assigned CVE-2013-1493.

Record

Document
The Java Zero-Day Procession Continues
Researcher
Brian Donohue
Published by
Threatpost | The first stop for security news
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Brian Donohue, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .