Vulnerabilities > CVE-2002-1292 - Unspecified vulnerability in Microsoft Java Virtual Machine 1.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS02-052.NASL |
description | The remote host is running a Microsoft VM machine that has a bug in its bytecode verifier that could allow a remote attacker to execute arbitrary code on this host, with the privileges of the SYSTEM. To exploit this vulnerability, an attacker would need to send a malformed applet to a user on this host, and have him execute it. The malicious applet would then be able to execute code outside the sandbox of the VM. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11177 |
published | 2002-11-28 |
reporter | This script is Copyright (C) 2002-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11177 |
title | MS02-052: Flaw in Microsoft VM Could Allow Code Execution (810030) |
code |
|
References
- http://marc.info/?l=bugtraq&m=103682630823080&w=2
- http://marc.info/?l=bugtraq&m=103682630823080&w=2
- http://marc.info/?l=ntbugtraq&m=103684360031565&w=2
- http://marc.info/?l=ntbugtraq&m=103684360031565&w=2
- http://www.kb.cert.org/vuls/id/237777
- http://www.kb.cert.org/vuls/id/237777
- http://www.securityfocus.com/bid/6133
- http://www.securityfocus.com/bid/6133
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-069
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-069
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10585
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10585