Vulnerability Name:

CVE-2009-1672 (CCN-50629)

Assigned:2009-05-13
Published:2009-05-13
Updated:2017-09-29
Summary:The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2009-1672

Source: CCN
Type: Sun Web site
Java Runtime Environment ActiveX control

Source: CCN
Type: OSVDB ID: 56402
Sun Java SE Runtime Environment Deployment Toolkit ActiveX (deploytk.dll) launch Method .jnlp URL Arbitrary Code Execution

Source: CCN
Type: OSVDB ID: 56403
Sun Java SE Runtime Environment Deployment Toolkit ActiveX (deploytk.dll) install*JRE Method Privilege Escalation

Source: BID
Type: Exploit
34931

Source: CCN
Type: BID-34931
Sun Java Runtime Environment ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities

Source: MISC
Type: Exploit
http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.html

Source: XF
Type: UNKNOWN
sun-jre-activex-code-execution(50629)

Source: XF
Type: UNKNOWN
sun-jre-activex-code-execution(50629)

Source: EXPLOIT-DB
Type: UNKNOWN
8665

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:jre:6:update_13:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sun:jre:1.6.0:update13:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun jre 6 update_13
    sun jre 1.6.0 update13