CVE-2010-1423

Java NPAPI/Deployment Toolkit <6-19 - Command Injection

Title source: llm
STIX 2.1

Description

Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/41700
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/java_ws_arginject_altjvm.rb

Scores

EPSS 0.6895
EPSS Percentile 98.6%

Details

CWE
CWE-78
Status published
Products (4)
oracle/jdk 1.6.0 update10
oracle/jdk < 1.6.0
oracle/jre 1.6.0 update_10
oracle/jre < 1.6.0
Published Apr 15, 2010
Tracked Since Feb 18, 2026