Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v10.5 - Exploits Update (Fri Nov 05 2010)

Oracle Java docBase Parameter Buffer Overflow Exploit Update

Exploits/Client Side  [Windows]




• Fri Nov 05 2010
The Java plugin for Internet Explorer (jp2iexp.dll) is affected by a stack-based buffer overflow when processing the docBase parameter of a Java applet. This can be exploited to execute arbitrary code with the privileges of the current user by enticing the victim to visit a malicious web page. This update adds DEP bypassing capability to the exploit, and adds support for Windows 7, Windows Server 2008, and Internet Explorer 8.

Exploits Vulnerabiltiy: CVE-2010-3552



< Back to Product Updates