bk99.de entertain the web since 1997

Critical security hole in the Security Manager

Summary

In January 2013 an already actively exploited hole became known in the Security Manager of Java 7 up to and including Update 10. A combination of JMX MBean and internal JavaScript classes in an applet could be used to bypass the Security Manager and execute code from websites. US-CERT recommended disabling Java in the browser; there was no patch from Oracle yet.

Ideas

  • The Security Manager was meant to lock applets in, but could be bypassed.
  • A security researcher with the alias Kafeine found the exploit already in use.
  • Java versions older than 7 were not affected.
  • The only protective measure was to switch off Java in the browser.
  • The exploit was already in exploit kits such as Nuclear Pack, Redkit and Blackhole.

Insights

  • Sandboxing within a complex runtime environment has a huge attack surface.
  • Repeated zero-days permanently undermined trust in browser plugins.

Facts

  • Java 7 up to and including Update 10 was affected.
  • The bug was in the Security Manager of JRE 1.7.

References

Critique

  • The report names CVE-2012-4681, the identifier of a Java hole from August 2012; the hole exploited in January 2013 is listed as CVE-2013-0422.

Recommendations

  • Uninstall browser plugins such as Java that you do not need.
  • Isolate legacy applications that require Java applets in a separate virtual environment.

Read the original article

Search the Web Archive