CVE-2009-1672
The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.
- Affected products
- Sun Java Runtime Environment
- Sun Jre
- = 6
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 9.6% (95th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2009-05-18
CVE-2009-1672 at NVD
1 known exploit for CVE-2009-1672
Proof-of-concept code and exploit modules indexed by Sploitus