Critical security hole in the Security Manager
Summary
In January 2013 an already actively exploited hole became known in the Security Manager of Java 7 up to and including Update 10. A combination of JMX MBean and internal JavaScript classes in an applet could be used to bypass the Security Manager and execute code from websites. US-CERT recommended disabling Java in the browser; there was no patch from Oracle yet.
Ideas
- The Security Manager was meant to lock applets in, but could be bypassed.
- A security researcher with the alias Kafeine found the exploit already in use.
- Java versions older than 7 were not affected.
- The only protective measure was to switch off Java in the browser.
- The exploit was already in exploit kits such as Nuclear Pack, Redkit and Blackhole.
Insights
- Sandboxing within a complex runtime environment has a huge attack surface.
- Repeated zero-days permanently undermined trust in browser plugins.
Facts
- Java 7 up to and including Update 10 was affected.
- The bug was in the Security Manager of JRE 1.7.
References
Critique
- The report names CVE-2012-4681, the identifier of a Java hole from August 2012; the hole exploited in January 2013 is listed as CVE-2013-0422.
Recommendations
- Uninstall browser plugins such as Java that you do not need.
- Isolate legacy applications that require Java applets in a separate virtual environment.
Links to the original source and the Web Archive open in a new tab.