Java zero-day exploit reportedly for sale

By
Follow google news

Affects latest platform version.

A zero-day exploit against the latest version of Java is reportedly up for sale on online cybercrime forums.

Java zero-day exploit reportedly for sale

The seller had asked for a five-figure sum for the exploit which targeted a vulnerability within the Java Class MidiDevice.Info, Krebsonsecurity reported.

The exploit was reportedly successfully tested against Java 7 Update 9 running on Firefox and Internet Explorer on Windows 7 machines, and would be sold only once.

It was the latest in a string of attacks against Java, considered by many to be a security risk due to its complexity, popularity and that it runs cross-platform.

The recent attacks have spurred security experts to recommend uninstalling Java from web browsers unless it is needed, while Apple last month removed the Java plug-in from Safari.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Supply chain attack hits 100 million-download Axios npm package

Supply chain attack hits 100 million-download Axios npm package

NAB is co-designing a SIEM with Databricks

NAB is co-designing a SIEM with Databricks

APRA pulls data submission system after security pentest

APRA pulls data submission system after security pentest

Councils push for federal shared security centre funding

Councils push for federal shared security centre funding

Log In

  |  Forgot your password?