CVE-2009-1672
The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 9.64% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- sun/jre
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/34931Exploit
- http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.htmlExploit, URL Repurposed
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50629
- https://www.exploit-db.com/exploits/8665
- http://www.securityfocus.com/bid/34931Exploit
- http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.htmlExploit, URL Repurposed
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50629
- https://www.exploit-db.com/exploits/8665
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.