Short Name |
SMB:ORACLE-JRE-INSECURE-LOAD |
---|---|
Severity |
Medium |
Recommended |
No |
Recommended Action |
Drop |
Category |
SMB |
Keywords |
Oracle Java Runtime Environment Insecure File Loading |
Release Date |
2011/07/25 |
Update Number |
1960 |
Supported Platforms |
idp-4.1.110110609+, isg-3.4.139899+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability in Oracle Java Runtime Environment. It is due to a design weakness in loading configuration files. Remote attackers can exploit this by enticing target users to download a malicious dll file from an SMB share. A successful attack can result in loading the attacker-controlled library and execution of arbitrary code with the privileges of the logged-in user. If a user is logged-on with administrative user rights, an attacker can take complete control of the affected system.