CVE-2009-1672
Last modified
CVE-2009-1672 is a vulnerability of currently unknown severity. The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.. EPSS estimates a 9.64% chance of exploitation in the next 30 days.
Description
The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sun | Jre | 6 | Update 13 |
References
- http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.htmlExploit, URL Repurposed
- http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.htmlExploit, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1672?
How severe is CVE-2009-1672?
How do I fix CVE-2009-1672?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-1666Multiple unspecified vulnerabilities in CycloMedia CycloScop…
- CVE-2009-1667Stack-based buffer overflow in Mini-stream CastRipper 2.50.7…
- CVE-2009-1668TYPSoft FTP Server 1.11 allows remote attackers to cause a d…
- CVE-2009-1669The smarty_function_math function in libs/plugins/function.m…
- CVE-2009-1670user/index.php in TCPDB 3.8 does not require administrative …
- CVE-2009-1671Multiple buffer overflows in the Deployment Toolkit ActiveX …
- CVE-2009-1673The kernel in Sun Solaris 9 allows local users to cause a de…
- CVE-2009-1674Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allo…
- CVE-2009-1675Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.2…
- CVE-2009-1676Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2009-1677Multiple static code injection vulnerabilities in the saveFe…
- CVE-2009-1678Directory traversal vulnerability in the saveFeed function i…
Are you affected by CVE-2009-1672?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
