| Vulnerability Name: | CVE-2000-0327 (CCN-3378) | ||||||||
| Assigned: | 1999-10-21 | ||||||||
| Published: | 1999-10-21 | ||||||||
| Updated: | 2018-10-12 | ||||||||
| Summary: | Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability. | ||||||||
| CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Thu, 14 Oct 1999 10:12:28 -0400 Another Microsoft Java Flaw Disovered Source: MITRE Type: CNA CVE-1999-0766 Source: MITRE Type: CNA CVE-2000-0327 Source: BUGTRAQ Type: UNKNOWN 19991014 Another Microsoft Java Flaw Disovered Source: CCN Type: CIAC Information Bulletin K-005 Microsoft "Virtual Machine Verifier" Vulnerability Source: CCN Type: Microsoft Security Bulletin MS02-013 04 March 2002 Cumulative VM Update Source: CCN Type: Microsoft Security Bulletin MS02-069 Flaw in Microsoft VM Could Enable System Compromise (810030) Source: CCN Type: Microsoft Security Bulletin MS03-011 Flaw in Microsoft VM Could Enable System Compromise (816093) Source: CCN Type: Microsoft Security Bulletin MS99-031 Patch Available for 'Virtual Machine Sandbox' Vulnerability Source: CCN Type: Microsoft Security Bulletin MS99-045 Patch Available 'Virtual Machine Verifier' Vulnerability Source: CCN Type: OSVDB ID: 1056 Microsoft Java Virtual Machine Sandbox Bypass Source: CCN Type: OSVDB ID: 8053 Microsoft Virtual Machine Illegal Cast Operation Command Execution Source: CCN Type: BID-600 Microsoft IE Virtual Machine Sandbox Vulnerability Source: CCN Type: BID-740 Microsoft Java Virtual Machine Class Cast Vulnerability Source: CCN Type: SmartComputing Reference Series Article, May 2001, Vol.5 Issue 2, Page(s) 20-22 in print issue Pouring On The Java: Use Of Java & Java Applets Gets More Popular On The Web Source: MS Type: UNKNOWN MS99-045 Source: XF Type: UNKNOWN msvm-verifier-java(3378) Source: CCN Type: Microsoft Knowledge Base Article 240346 Malicious Java Applet May Be Able to Read, Write, or Delete Files on the Computer of a Web Site Visitor | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||