Exploitation Summary
EIP tracks 2 public exploits for CVE-2012-1533.
PoCs published by Rh0, including Metasploit module exploits/windows/browser/java_ws_double_quote.
AI-analyzed exploit summary This Metasploit module exploits a flaw in Java Web Start (JNLP) where improper sanitization of double quotes in heap-size parameters allows injection of the -XXaltjvm option, leading to remote code execution via a malicious jvm.dll loaded from a UNC path.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-3159.
Exploits (2)
This Metasploit module exploits a flaw in Java Web Start (JNLP) where improper sanitization of double quotes in heap-size parameters allows injection of the -XXaltjvm option, leading to remote code execution via a malicious jvm.dll loaded from a UNC path.
This Metasploit module exploits a flaw in Java Web Start (CVE-2012-1533) by injecting a double quote into JNLP parameters, allowing the -XXaltjvm option to load a malicious jvm.dll from a remote UNC path, achieving arbitrary code execution.