Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 10th, 2013, 14:29 GMT · By

BLOG

Expert Finds Java 1.7 Zero-Day on High-Profile Website

SHARE:

Adjust text size:


New Java zero-day found Enlarge picture - New Java zero-day found
The security expert known as Kafeine, the curator of the Malware Don’t Need Coffee website, has come across a new Java zero-day.

The vulnerability affects the latest Java 1.7 and it has been found on a website that allegedly records hundreds of thousands of hits each day.

Experts from AlienVault have analyzed the exploit and they've shown that a malicious Java applet can be used to execute code (in their example, the Calculator application from Windows).

“The Java file is highly obfuscated but based on the quick analysis we did the exploit is probably bypassing certain security checks tricking the permissions of certain Java classes as we saw in CVE-2012-4681,” AlienVault’s Jaime Blasco explained.

Researchers from Bitdefender are also analyzing the zero-day which, they say, has been integrated into the recently developed Cool exploit kit.

While more details of the vulnerability come to light, experts advise users to disable Java and avoid clicking on suspicious links.

TELL US WHAT YOU THINK:

2,005 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Java JRE 7 Zero-Day Sold on Underground Market for Five-Digit Sum

Dockster Mac Malware Planted on Website Dedicated to Dalai Lama

Even Small and Unimportant Security Bugs Matter in Java, Experts Say

BlackHole Author Now Rents Cool Exploit Kit for $10,000 (8,000 EUR) per Month

Cybercriminals Hack DNS Records of Go Daddy Sites to Distribute Ransomware

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM