SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-1286

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an…

HIGH 7.5EPSS 20.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 20.5%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
20.50% probability · 97th percentile
CISA KEV
Not listed
Affected
microsoft/java virtual machine
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.