Description
Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/41700
metasploit
WORKING POC
EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/java_ws_arginject_altjvm.rb
References (9)
Scores
EPSS
0.6895
EPSS Percentile
98.6%
Details
CWE
CWE-78
Status
published
Products (4)
oracle/jdk
1.6.0 update10
oracle/jdk
< 1.6.0
oracle/jre
1.6.0 update_10
oracle/jre
< 1.6.0
Published
Apr 15, 2010
Tracked Since
Feb 18, 2026