Short Name |
TROJAN:BYTE-VERIFY-HTML |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
TROJAN |
Keywords |
Byte-Verify in Webpage |
Release Date |
2005/01/05 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects the Trojan Byte-Verify within an HTML document loaded from a web page. An attacker could exploit the vulnerability in the ByteCode verifier component of Microsoft Virtual Machine to execute arbitrary code with the privileges of the current user.
The Microsoft Java virtual machine implementation contains a vulnerability that may allow for malicious Java applets to escape the security sandbox. An applet constructed at the bytecode-level may be able to perform some illegal operations. If these operations are performed, it may be possible to escape the security constraints placed on the applet by the JVM. Code execution with the privileges of the victim user may be possible.