Microsoft JVM Unauthorized Clipboard Access Vulnerability
BID:6132
Info
Microsoft JVM Unauthorized Clipboard Access Vulnerability
| Bugtraq ID: | 6132 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-1290 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2002 12:00AM |
| Updated: | Jul 11 2009 06:07PM |
| Credit: | Discovered by Jouko Pynnonen <[email protected]>. |
| Vulnerable: |
Microsoft JVM 1.1 |
| Not Vulnerable: | |
Discussion
Microsoft JVM Unauthorized Clipboard Access Vulnerability
The Microsoft JVM implements the Java runtime environment for Microsoft Internet Explorer. A vulnerability has been discovered Microsoft's implementation of the Java Virtual Machine (JVM).
Through the use of various 'INativeServices' class methods, in a malicious Java applet, it is possible for a remote attacker to read and modify the contents of a vulnerable users clipboard.
Exploiting this vulnerability may allow a remote attacker to read and modify sensitive information stored in a users clipboard.
This vulnerability was originally reported in BID 5670.
The Microsoft JVM implements the Java runtime environment for Microsoft Internet Explorer. A vulnerability has been discovered Microsoft's implementation of the Java Virtual Machine (JVM).
Through the use of various 'INativeServices' class methods, in a malicious Java applet, it is possible for a remote attacker to read and modify the contents of a vulnerable users clipboard.
Exploiting this vulnerability may allow a remote attacker to read and modify sensitive information stored in a users clipboard.
This vulnerability was originally reported in BID 5670.
Exploit / POC
Microsoft JVM Unauthorized Clipboard Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.