Web Hack List

Other nomination

Fireeye -- Arbitrary reading and writing of the JVM process

A Java zero-day found exploited in the wild against Java 6u41 and 7u15. Instead of the usual sandbox-permission tricks it targets the JVM's internal data structures for arbitrary memory read and write, zeroing memory to fetch a McRAT payload. It is unreliable and often crashes the JVM; Oracle assigned CVE-2013-1493.

Record

Researcher
Brian Donohue
Published by
Threatpost | The first stop for security news
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Brian Donohue, first published at the original source. Preserved copies are kept so the citation survives its host.