[FSec] CVE-2013-2423 Java Vulnerability Exploit ITW

Newsfeed

Nachrichtenbote
A few days after Oracle released a critical patch, CVE-2013-2423 is found to already been exploited. Upon checking the history, the exploitation seems to have begun on April 21st and is still actively happening until a few hours ago:

url_list.png


For a closer look, the image below contains a comparison of the classes found in the Metasploit module and that of the ITW sample:

Metasploit.png


Interestingly, the Metasploit module was published on the 20th, and as mentioned earlier, the exploit was seen in the wild the day after.

Information about the PoC can be found here.

Files are detected as Exploit:Java/Majava.B.

Sample hashes:
1a3386cc00b9d3188aae69c1a0dfe6ef3aa27bfa
23acb0bee1efe17aae75f8138f885724ead1640f



Post by - Karmina and @Timo
On 23/04/13 At 02:36 PM

Weiterlesen...
 
Zurück
Oben