Vulnerabilities > CVE-2002-0076
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 13 | |
Application | 3 | |
Application | 1 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS02-013.NASL |
description | The Microsoft VM is a virtual machine for the Win32 operating environment. There are numerous security flaws in the remote Microsoft VM that could allow an attacker to execute arbitrary code on this host. To exploit these flaws, an attacker would need to set up a malicious web site with a rogue Java applet and lure the user of this host to visit it. The Java applet could then execute arbitrary commands on this host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11326 |
published | 2003-03-06 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11326 |
title | MS02-013: Cumulative VM Update (300845) |
code |
|
References
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/218
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/218
- http://www.iss.net/security_center/static/8480.php
- http://www.iss.net/security_center/static/8480.php
- http://www.securityfocus.com/bid/4313
- http://www.securityfocus.com/bid/4313
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-013
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-013