Other nomination
Fireeye -- Arbitrary reading and writing of the JVM process
A Java zero-day found exploited in the wild against Java 6u41 and 7u15. Instead of the usual sandbox-permission tricks it targets the JVM's internal data structures for arbitrary memory read and write, zeroing memory to fetch a McRAT payload. It is unreliable and often crashes the JVM; Oracle assigned CVE-2013-1493.
Record
- Researcher
- Brian Donohue
- Published by
- Threatpost | The first stop for security news
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Brian Donohue, first published at the original source. Preserved copies are kept so the citation survives its host.