Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Editor Blogs > Security

August 27th, 2012, 08:28 GMT · By

BLOG

Zero-Day Vulnerability in Java Exploited in Targeted Attacks, FireEye Finds

SHARE:

Adjust text size:


Zero-day flaw in Java identified Enlarge picture - Zero-day flaw in Java identified
Security researchers from FireEye have identified a new Java zero-day vulnerability that’s currently being exploited in a limited number of targeted attacks.

According to experts, most of the recent Java run-time environments (JRE) are affected and, for the time being, there are no known mitigations.

The exploit has been found on a domain – registered to an IP address from China – that’s currently still active.

If users visit the malicious domain, they’re served a nasty piece of malware identified as Dropper.MsPMs. The dropper communicates with a command and control server domain from Singapore.

The proof-of-concept is expected to become public any day now, allowing other cybercriminals to utilize it as well. Hopefully, Oracle will act on addressing this issue as soon as possible, even though they don't usually release out-of-band patches.
FILED UNDER:
zero-day
Java
vulnerability

TELL US WHAT YOU THINK:

1,348 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


DHS Warns of SSL Traffic Interception Flaw in ROS-Based Devices

Flash Player Updated to Prevent Attackers from Taking Control of Devices

DARPA Wants to Dominate Cyber Battlespace with Plan X

Crisis Spreads to Macs, Windows Computers, Mobile Devices and Virtual Machines

Hacker Accuses Firm of Failing to Secure Sites of Professional Indian Cricket Players

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM