Collected research
Fireeye -- Arbitrary reading and writing of the JVM process
The Java Zero-Day Procession Continues
A Java zero-day found exploited in the wild against Java 6u41 and 7u15. Instead of the usual sandbox-permission tricks it targets the JVM's internal data structures for arbitrary memory read and write, zeroing memory to fetch a McRAT payload. It is unreliable and often crashes the JVM; Oracle assigned CVE-2013-1493.
Record
- Document
- The Java Zero-Day Procession Continues
- Researcher
- Brian Donohue
- Published by
- Threatpost | The first stop for security news
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Brian Donohue, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .