Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v12 - Exploits Update (Thu Nov 10 2011)

Oracle Java Rhino Script Engine Remote Code Execution Exploit

Exploits/Client Side  [Windows]




Thu Nov 10 2011
The Rhino Script Engine of Oracle Java fails to properly check for permissions on JavaScript error objects. This flaw allows an unprivileged applet to escape the sandbox and execute arbitrary code on the target machine with the privileges of the current user.

Exploits Vulnerabiltiy: CVE-2011-3544



< Back to Product Updates