Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

November 28th, 2012, 08:48 GMT · By

BLOG

Java JRE 7 Zero-Day Sold on Underground Market for Five-Digit Sum

SHARE:

Adjust text size:


Java JRE 7 zero-day sold on underground market Enlarge picture - Java JRE 7 zero-day sold on underground market
A new Java zero-day is currently being sold on the underground market by a cybercriminal who’s asking a five-digit sum for the exploit.

According to Brian Krebs, the unpatched vulnerability affects all versions of Java JRE 7, but it doesn’t impact Java 6 or earlier variants.

The seller claims that the vulnerability exists in the MidiDevice.info class, which is responsible for handling audio input and output.

The exploit is allegedly very reliable for code execution, being tested with Firefox and MSIE on Windows 7.

Although the exact price hasn’t been revealed, the cybercriminal says he will only sell it “one time” for a five-figure sum.

On the other hand, who needs a zero-day when Oracle still hasn’t fixed an issue discovered months ago?

Although Security Explorations experts have demonstrated that the security hole which affects Java 5, 6 and 7 can be patched up in a matter of 30 minutes, Oracle seems determined to keep to its CPU release schedule and address the issue only in February 2013.

TELL US WHAT YOU THINK:

2,074 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Expert Finds 23 Security Holes in Schneider, Rockwell, Other SCADA Systems

VUPEN Researchers Find Windows 8 Zero-Day, All Exploit Mitigations Bypassed (Updated)

Hacker Sells Yahoo! Mail Zero-Day for $700 (€550) – Video

Adobe Reader Zero-Day Still Unfixed, Researchers Fail to Provide POC

Skype 0-Day Vulnerability Allowed Hackers to Change the Password of Any Account – Video

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM