CVE-2009-1672
Last modified
CVE-2009-1672 is a vulnerability of currently unknown severity. The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.. EPSS estimates a 9.64% chance of exploitation in the next 30 days.
Description
The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sun | Jre | 6 | Update 13 |
References
- http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.htmlExploit, URL Repurposed
- http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.htmlExploit, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1672?
How severe is CVE-2009-1672?
How do I fix CVE-2009-1672?
Are you affected by CVE-2009-1672?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
