CVE-2000-0132

Microsoft Java Virtual Machine - Unauthenticated Arbitrary File Read via getSystemResourceAsStream

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0132. PoCs published by Hiromitsu Takagi.

AI-analyzed exploit summary This exploit leverages Microsoft's Java Virtual Machine vulnerability to read local files via getSystemResourceAsStream() or verify file existence via getSystemResource(). It allows remote Java applications to access files in specific paths or traverse directories.

Description

Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Hiromitsu Takagi · javaremotewindows
https://www.exploit-db.com/exploits/19734

This exploit leverages Microsoft's Java Virtual Machine vulnerability to read local files via getSystemResourceAsStream() or verify file existence via getSystemResource(). It allows remote Java applications to access files in specific paths or traverse directories.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Java Virtual Machine (IE 4/5)
No auth needed
Prerequisites: Victim must run a vulnerable version of Microsoft JVM · Attacker must deliver the malicious applet to the victim
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/957

Scores

EPSS 0.1954
EPSS Percentile 97.0%

Details

CWE
CWE-200
Status published
Products (2)
microsoft/virtual_machine 2000
microsoft/virtual_machine 3000
Published Jan 31, 2000
Tracked Since Feb 18, 2026