vendor:
Java JRE
by:
Tavis Ormandy
7.5
CVSS
HIGH
Logic Flaw
CWE
Product Name: Java JRE
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Logic flaw in Java JRE with backdoor potential
The method in which Java Web Start support has been added to the JRE is not less than a deliberately embedded backdoor or a flagrant case of extreme negligence. The code snippet provided shows a subroutine that is responsible for opening a registry key with the path "JNLPFileShellOpenCommand" and it sets the desired access rights and options. This vulnerability can potentially allow an attacker to execute arbitrary code or perform unauthorized actions on the affected system.
Mitigation:
Update to the latest version of Java JRE and ensure that all security patches are applied. Additionally, consider disabling Java in web browsers if it is not required.